CVE-2025-12490
8.8Netgate · pfSense CE
A path traversal vulnerability in the Netgate pfSense Suricata package allows authenticated remote attackers to achieve arbitrary file creation with root privileges.
Executive summary
An authenticated path traversal vulnerability in the Netgate pfSense Suricata package permits remote attackers to execute arbitrary file operations with root-level privileges.
Vulnerability
This is a path traversal vulnerability (CWE-22) residing in the Suricata package component. It occurs due to insufficient validation of user-supplied paths before file system operations, allowing an authenticated attacker to write files as the root user.
Business impact
The ability to create arbitrary files as root on a firewall appliance represents a total compromise of the security boundary. An attacker could overwrite critical system configuration files, deploy malicious binaries, or disrupt network traffic, leading to full system control and potential network-wide security failures. The CVSS score of 8.8 reflects the high severity of this flaw, as it allows for complete system impact despite the requirement for authenticated access.
Remediation
Immediate Action: Update the Suricata package to the patched version identified in the vendor advisory and apply all available system updates for pfSense 2.8.1.
Proactive Monitoring: Review system and authentication logs for unauthorized file modification attempts or anomalous activity associated with the Suricata service account.
Compensating Controls: Restrict access to the pfSense web management interface to trusted administrative IP addresses and enforce strong, multi-factor authentication for all administrative accounts to minimize the risk of unauthorized access.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the potential for complete system compromise and the critical role of pfSense as a network security appliance, administrators must prioritize patching the Suricata package. Ensure that administrative access is strictly controlled and monitored to prevent the authentication prerequisite from being satisfied by malicious actors. Failure to remediate this vulnerability significantly increases the risk of persistent, high-privilege access within the network infrastructure.
Sources
- ZDI-25-979
- vendor-provided URL Vendor advisory