module
pfSense Diag Routes Web Shell Upload
Disclosed | Created |
---|---|
2022-02-23 | 2022-03-04 |
Disclosed
2022-02-23
Created
2022-03-04
Description
This module exploits an arbitrary file creation vulnerability in the pfSense
HTTP interface (CVE-2021-41282). The vulnerability affects versions
and can be exploited by an authenticated user if they have the
"WebCfg - Diagnostics: Routing tables" privilege.
This module uses the vulnerability to create a web shell and execute payloads
with root privileges.
HTTP interface (CVE-2021-41282). The vulnerability affects versions
and can be exploited by an authenticated user if they have the
"WebCfg - Diagnostics: Routing tables" privilege.
This module uses the vulnerability to create a web shell and execute payloads
with root privileges.
Authors
Abdel Adim "smaury" Oisfi of Shielder
jbaines-r7
jbaines-r7
Platform
BSD,Unix
Architectures
cmd, x64
References
Module Options
To display the available options, load the module within the Metasploit console and run the commands ‘show options’ or ‘show advanced’:

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.