← Back

CVE-2025-34312

nvd nist
Published: Oct 28, 2025Modified: Nov 3, 2025

JSON object

Loading...
8.7
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: disclosure@vulncheck.com (Secondary)

Description

IPFire versions prior to 2.29 (Core Update 198) contain a command injection vulnerability that allows an authenticated attacker to execute arbitrary commands as the 'nobody' user via the BE_NAME parameter when installing a blacklist. When a blacklist is installed the application issues an HTTP POST to /cgi-bin/urlfilter.cgi and interpolates the value of BE_NAME directly into a shell invocation without appropriate sanitation. Crafted input can inject shell metacharacters, leading to arbitrary command execution in the context of the 'nobody' user.

Affected (16)

Products: Ipfire: Ipfire
1 product
Ipfire
Configuration A
16 vulnerable
Vulnerable SoftwareAffected Versions
Ipfire
Before 2.29
Version 2.29 core_update183
Version 2.29 core_update184
Version 2.29 core_update185
Version 2.29 core_update186
Version 2.29 core_update187
Version 2.29 core_update188
Version 2.29 core_update189
Version 2.29 core_update190
Version 2.29 core_update191
Version 2.29 core_update192
Version 2.29 core_update193
Version 2.29 core_update194
Version 2.29 core_update195
Version 2.29 core_update196
Version 2.29 core_update197

References (3)

Source: disclosure@vulncheck.com
Issue TrackingThird Party Advisory
Source: disclosure@vulncheck.com
Release Notes

Timeline

No history available yet.