-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 ============================================================================= pfSense-SA-26_07.webgui Security Advisory pfSense Topic: Authenticated Command Execution via OpenVPN Settings Category: pfSense Base System Module: webgui Announced: 2026-08-13 Credits: @lujiefsi Affects: pfSense Plus software versions < 26.07 pfSense CE software versions <= 2.8.1 Corrected: 2026-06-17 19:46:45 UTC (pfSense Plus master, 26.10) 2026-06-17 19:49:14 UTC (pfSense Plus plus-RELENG_26_07, 26.07) 2026-06-17 19:46:45 UTC (pfSense CE master, 2.9.0) 0. Revision History v1.0 2026-08-13 Initial SA draft I. Background pfSense® software is a free network firewall distribution based on the FreeBSD operating system. The pfSense software distribution includes third- party free software packages for additional functionality, and provides most of the functionality of common commercial firewalls. pfSense® Plus is the productized version of pfSense software from Netgate®, previously referred to as pfSense Factory Edition (FE). It is available to Netgate appliance and CSP customers. The majority of users of pfSense software have never installed or used a stock FreeBSD system. Unlike similar GNU/Linux-based firewall distributions, there is no need for any UNIX knowledge. The command line is never used, and there is no need to ever manually edit any rule sets. Instead, pfSense software includes a web interface for the configuration of all included components. Users familiar with commercial firewalls will quickly understand the web interface, while those unfamiliar with commercial-grade firewalls may encounter a short learning curve. II. Problem Description A potential authenticated arbitrary command execution vulnerability was found that uses the OpenVPN server settings on vpn_openvpn_server.php, a component of the pfSense Plus and pfSense CE software GUI. The settings for dns_domain and netbios_scope on vpn_openvpn_server.php accept CR/LF characters and other characters which are not valid for their content, such as double quotes, which can lead to a potential command execution path. This problem is present on pfSense Plus version 26.03.1, pfSense CE version 2.8.1, and earlier versions of both. III. Impact Due to a lack of validation on the affected parameters, specially-crafted payloads can allow adding arbitrary OpenVPN configuration directives, including directives which execute external commands such as "up" and "route-up". Users must be authenticated and have privileges to access vpn_openvpn_server.php to trigger the issue. The OpenVPN advanced options already allow using these directives by design, however, access to the OpenVPN advanced options is controlled by a separate privilege which may not have been granted to a user. IV. Workaround To help mitigate the problem on older releases, use one or more of the following: * Limit access to the affected pages to trusted administrators only. V. Solution Users can upgrade to pfSense Plus software version 26.07 or later, or pfSense CE software versions after 2.8.1 when available. This upgrade may be performed in the web interface or from the console. See https://docs.netgate.com/pfsense/en/latest/install/upgrade-guide.html Users on pfSense Plus version 26.03.1 and pfSense CE version 2.8.1 may apply the fix from the recommended patches list in the System Patches package after installing or updating the System Patches package. Users may also manually apply the relevant changes using the System Patches package on earlier versions, or by manually making similar changes to the affected files if the patches do not apply directly. See https://docs.netgate.com/pfsense/en/latest/development/system-patches.html VI. Correction details The following list contains the correction revision commit ID for each affected item. Branch/path Revision - - ------------------------------------------------------------------------- plus/plus-master fd301381e29f6fb217d1388ed56581e9b4ad6186 plus/plus-RELENG_26_07 605e825a25648d7f528922ee9b886aeeb06a0844 pfSense/master fd301381e29f6fb217d1388ed56581e9b4ad6186 - - ------------------------------------------------------------------------- VII. References The latest revision of this advisory is available at -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE40XvjEU56XSUPIMdE7mH/ZIU+NoFAmp+HpEACgkQE7mH/ZIU +Np5Ag/+LNGZwcUyHtApUJrVtT419QV3RO4LP+vcGwh18nFyQutUu5zbYCR3n6td DapUoOIRAg4TLD4upXXDlpLA6/FROYL4CsW0rl5OAiIHNIbAf5ehP2CLiHJDIUNX YovBo3k5zkw32/ACNN7+TMlL+Rj95O/EzBpNMCSqhWJiiDD0eUDSELBiOmzVQsOd FPiLcmIXcEQcg43G90yckRTRYRBF5a7IF9OiOMPoOqIMjMmppGUL2C0lCvxcbE3n iph6eaXNU1foOXFe+zswutKiJY00+hF7nAuXhb2xhE2zltsr7xvc+C1moTtjeB6V rXZiByfuh+UZdSspFPTNqQbXYn+COp8R+vBUzfjie6OFEGWmHMwl4ALYQkBFiwDy hHKd6Yj6E2srw/BP8qA540ptMOX1ZVqROofgltjO/m4GLsgMN6St/8KD8j9MGdcG +2XPoKWM9AbIvK0ZVcA2FbIkr0T34gzepZ9mn+8/1BqrdRirnr+mJFUefrGlW0uI Z4z/gm4XbJ8j4KkmzBa9nJgGZv4SGV1QSVtZL4XJlHKObnD8oFBEArT0JiZjNmeQ GACEYfVHbgvLDKXaTpMf+4SumU+Qo1RGNqK7V2sQuTC8rba1hY948U9eCEa9R8fm +9NO7GCTD41dIupTsNc5ug1oRigfJp7zf61Sq/oIpyjNpKAU98w= =kQuR -----END PGP SIGNATURE-----