CVE-2021-41282
CVSS v3
8.8
HIGH
Score EPSS
87.1 %
probabilité d’exploitation au 2026-10-05
CISA KEV
Non
exploitation connue
Exploitation
—
statut SSVC
Description
diag_routes.php in pfSense 2.5.2 allows sed data injection. Authenticated users are intended to be able to view data about the routes set in the firewall. The data is retrieved by executing the netstat utility, and then its output is parsed via the sed utility. Although the common protection mechanisms against command injection (i.e., the usage of the escapeshellarg function for the arguments) are used, it is still possible to inject sed-specific code and write an arbitrary file in an arbitrary location.
Détails techniques
- Publiée le
- 2022-03-01
Questions fréquentes
Qu’est-ce que CVE-2021-41282 ?
diag_routes.php in pfSense 2.5.2 allows sed data injection. Authenticated users are intended to be able to view data about the routes set in the firewall. The data is retrieved by executing the netstat utility, and then its output is parsed via the sed utility. Although the common protection mechanisms against command injection (i.e., the usage of the escapeshellarg function for the arguments) are used, it is still possible to inject sed-specific code and write an arbitrary file in an arbitrary location.
CVE-2021-41282 est-elle activement exploitée ?
Aucune exploitation active de CVE-2021-41282 n’est confirmée. Son score EPSS était de 87.1 % au 2026-10-05, soit la probabilité estimée d’exploitation dans les 30 prochains jours.
Quel est le score CVSS de CVE-2021-41282 ?
CVE-2021-41282 a un score de base CVSS v3 de 8.8 (gravité HIGH).
CVE-2021-41282 touche-t-elle votre environnement ?
Utilisez isMalicious pour vérifier si l’une de vos IP ou l’un de vos domaines est associé aux IOC de cette vulnérabilité.
Sans carte bancaire · 50 vérifications gratuites par mois · Clé API gratuite
Autres vulnérabilités 2021 à trier
Classées par probabilité d’exploitation (EPSS).