AI description
CVE-2025-53392 affects Netgate pfSense CE version 2.8.0. It involves a directory traversal vulnerability within the "WebCfg - Diagnostics: Command" privilege, specifically allowing the reading of arbitrary files through the diag_command.php dlPath. The manipulation of the argument dlPath leads to absolute path traversal. The vulnerability is triggered when the "WebCfg - Diagnostics: Command" privilege is enabled. It should be noted that the vendor considers this behavior to be intended for the given privilege level, with administrators supposedly informed via documentation and the user interface.
- Description
- In Netgate pfSense CE 2.8.0, the "WebCfg - Diagnostics: Command" privilege allows reading arbitrary files via diag_command.php dlPath directory traversal. NOTE: the Supplier's perspective is that this is intended behavior for this privilege level, and that system administrators are informed through both the product documentation and UI.
- Source
- cve@mitre.org
- NVD status
- Awaiting Analysis
- CNA Tags
- disputed
CVSS 3.1
- Type
- Secondary
- Base score
- 5
- Impact score
- 1.4
- Exploitability score
- 3.1
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
- Severity
- MEDIUM
- cve@mitre.org
- CWE-36
- Hype score
- Not currently trending
💥CVE-2025-53392 has been published, marked as vendor disputed. I'm committed to holding vendors to a higher standard when it comes to security architecture and implementation. https://t.co/a0p5l687HP https://t.co/7ay0ojD1JJ
@skraft09
29 Jun 2025
38 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-53392 Netgate pfSense CE 2.8.0 Diagnostics Command Privilege Directory Travers... https://t.co/TkBOLlEgAX Vulnerability Notification: https://t.co/xhLrNnfyrO
@VulmonFeeds
29 Jun 2025
95 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-53392 In Netgate pfSense CE 2.8.0, the "WebCfg - Diagnostics: Command" privilege allows reading arbitrary files via diag_command.php dlPath directory traversal. NOTE: the S… https://t.co/BdCSjxSHsh
@CVEnew
28 Jun 2025
965 Impressions
1 Retweet
6 Likes
1 Bookmark
1 Reply
0 Quotes