CVE-2025-53392
Last modified
CVE-2025-53392 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. In Netgate pfSense CE 2.8.0, the "WebCfg - Diagnostics: Command" privilege allows reading arbitrary files via diag_command.php dlPath directory traversal. NOTE: the Supplier's perspective is that this is intended behavior for this privilege level, and that system administrators are informed through both the product documentation and UI.. EPSS estimates a 1.77% chance of exploitation in the next 30 days.
Description
In Netgate pfSense CE 2.8.0, the "WebCfg - Diagnostics: Command" privilege allows reading arbitrary files via diag_command.php dlPath directory traversal. NOTE: the Supplier's perspective is that this is intended behavior for this privilege level, and that system administrators are informed through both the product documentation and UI.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Pfsense | Pfsense | 2.8.0 |
References
- https://github.com/skraft9/pfsense-security-researchExploit, Third Party Advisory
- https://github.com/skraft9/pfsense-security-researchExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-53392?
How severe is CVE-2025-53392?
How do I fix CVE-2025-53392?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-53385Rejected reason: Not used
- CVE-2025-53386Rejected reason: Not used
- CVE-2025-53387Rejected reason: Not used
- CVE-2025-53388Rejected reason: Not used
- CVE-2025-5339The Ads Pro Plugin - Multi-Purpose WordPress Advertising Man…7.5
- CVE-2025-53391The Debian zuluPolkit/CMakeLists.txt file for zuluCrypt thro…9.3
- CVE-2025-53393In Akka through 2.10.6, akka-cluster-metrics uses Java seria…6
- CVE-2025-53394Paramount Macrium Reflect through 2025-06-26 allows attacker…7.7
- CVE-2025-53395Paramount Macrium Reflect through 2025-06-26 allows local at…7.7
- CVE-2025-53396Incorrect permission assignment for critical resource issue …7.3
- CVE-2025-53397A vulnerability exists in Advantech iView versions prior to …6.1
- CVE-2025-53398The Portrait Dell Color Management application 3.3.8 for Del…7.8
Are you affected by CVE-2025-53392?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
