漏洞描述 pfBlockerNG是一个热门的默认未安装的pfSense插件。通常用于阻止来自整个国家或IP范围的入站连接。其2.1.4_26及以下版本包含该漏洞,攻击者可以通过未经验证的RCE漏洞来实现root访问。
相关漏洞推荐 iis-put-getshell: IIS Put Getshell ruijie-excu-shell-disclosure: 锐捷交换机 WEB 管理系统 EXCU_SHELL 信息泄露 thinkcmf-write-shell: Thinkcmf write shell POC spring4shell-CVE-2022-22965: Spring Framework RCE via Data Binding on JDK 9+ POC CVE-2019-12725: Zeroshell 3.9.0 - Remote Command Execution POC CVE-2020-29390: Zeroshell 3.9.3 - Command Injection POC CVE-2021-41282: pfSense - Arbitrary File Write POC CVE-2022-31814: pfSense pfBlockerNG <=2.1..4_26 - OS Command Injection POC CVE-2022-40624: pfSense pfBlockerNG - OS Command Injection POC CVE-2019-12725: Zeroshell 3.9.0 Remote Command Execution POC china-telecom-f460-gateway-rce: 电信天翼网关 F460 web_shell_cmd.gch 远程命令执行漏洞 POC insecure-powershell-execution-policy: Insecure PowerShell Execution Policy - Detect POC natshell-arbitrary-file-read: Natshell Arbitrary File Read