pfSense Plus

Changes in this version of pfSense Plus software.

Aliases / Tables

  • Fixed: Potential XSS via URL Table Ports Alias content #16945

  • Fixed: URL tables cannot import content from tgz file URLs #16964

Captive Portal

  • Fixed: Captive Portal authentication failures from usernames containing special characters or long strings can cause ambiguous or confusing log messages #16922

Configuration Backend

  • Changed: Improve handling of OpenSSL encryption passphrase #16958

DHCP (IPv4)

  • Added: Option to control Kea log level #16230

  • Changed: Kea attempts DNS Registration when Unbound is disabled #16865

  • Fixed: Daemon configuration manipulation via CR/LF in ISC DHCP settings #16900

  • Fixed: Potential XSS in DHCPv4 Pool Descriptions #16940

  • Added: Kea Custom Configuration JSON privilege #16960

  • Fixed: Daemon configuration manipulation via CR/LF in ISC DHCP numbered option settings #16962

DHCP (IPv6)

  • Fixed: Potential XSS in DHCPv6 Pool Descriptions #16941

DHCP Relay

  • Fixed: DHCP relay does not respect configured CARP VIP status #15017

DNS Resolver

  • Fixed: Unbound configuration may be generated with duplicate interface bindings #16906

Dashboard

  • Fixed: Potential XSS in Dynamic DNS widget display of Custom and RFC2136 entries #16944

  • Fixed: Potential Local File Include vulnerability via Dashboard widget sequence data #16947

Diagnostics

  • Fixed: Potential stored XSS in browser.php used by diag_edit.php #16918

  • Changed: Add device_key to filtered tags list for status output #16959

Dynamic DNS

  • Fixed: All-Inkl Dynamic DNS responses are not parsed correctly #16218

  • Changed: Encode Dynamic DNS credentials when passed as URL parameters #16905

Gateway Monitoring

  • Changed: Improve gateway status consistency #16707

Gateways

  • Changed: Improve default gateway detection when gateways share the same address #16816

  • Fixed: Static route not removed when enabling dpinger_dont_add_static_route while a gateway monitor IP address is set #16861

IPsec

  • Fixed: IPsec Keep Alive does not update the gateway status #15087

  • Fixed: Potential XSS via IPsec Phase 1 descriptions while editing Phase 2 entries #16942

IPv6 Router Advertisements (radvd/rtsold)

  • Fixed: IPv6 Track Interfaces ignores the Disabled Router Advertisements mode #16925

Interfaces

  • Fixed: VXLAN interfaces are configured with an incorrect MTU after re-saving their parent interface #16823

  • Added: Set IP Alias VIP as the Router Advertisement source #16914

Logging

  • Fixed: Potential XSS via inline Firewall Log rule descriptions #16923

OpenVPN

  • Fixed: Alert about missing MTU settings for OpenVPN DCO tunnels on every boot #16938

  • Fixed: RADIUS authentication fails when attribute contains an invalid ACL #16863

  • Fixed: Potential command execution via CR/LF in OpenVPN settings #16899

Operating System

  • Fixed: Kernel on armv7 can fail to parse loader configuration files #16746

  • Fixed: Loader menu does not display the logo properly #16726

PPP Interfaces

  • Fixed: Potential XSS in PPP instance Provider and Plan fields #16943

Package System

  • Fixed: Error updating repository metadata at boot with certain packages installed #16784

RRD Graphs

  • Fixed: Multiple updaterrd.sh processes #16927

Rules / NAT

  • Fixed: Cannot add Port Forward with an unassociated filter rule #15346

  • Fixed: Same port forward on multiple WANs can generate a PF error due to Pure NAT mode NAT reflection #16783

  • Changed: Retain a copy of the failed ruleset when a filter reload fails #16796

  • Fixed: Potential stored XSS via Firewall Schedules #16924

  • Fixed: Filter rules created as part of NAT rules can have an invalid protocol value #16954

SNMP

  • Fixed: Memory leak in libpfctl causes bsnmpd memory usage to grow over time #16456

  • Fixed: Daemon configuration manipulation via CR/LF in SNMP settings #16901

System Logs

  • Changed: Exclude nginx logs from system.log #16826

Traffic Graphs

  • Fixed: Potential XSS in Traffic Graphs Display option #16976

  • Fixed: Traffic Graphs display option “Description” does not utilize DHCP static mapping descriptions #16979

Traffic Shaper (ALTQ)

  • Fixed: Traffic Shaper Wizard duplicates all firewall rules when no shaping options are enabled #16866

Wake on LAN

  • Changed: “Wake All” functionality on services_wol.php should only use POST #16961

Web Interface

  • Fixed: Potential command execution via CR/LF in System Proxy settings #16898

Wireless

  • Fixed: Interfaces Status shows an invalid SSID value for Wi-Fi interfaces #16769