{"id":"CVE-2022-31814","aliases":[],"url":"https://o3.security/vulnerability/CVE-2022-31814","summary":"pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the HTTP Host header. NOTE: 3.x is unaffected.","details":"pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the HTTP Host header. NOTE: 3.x is unaffected.","published":"2022-09-05T16:15:08.500","modified":"2026-06-17T04:46:21.937","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":10,"affectedPackages":[],"fix":{"url":"https://github.com/pfsense/FreeBSD-ports/pull/1169","label":"pfsense/FreeBSD-ports#1169"},"references":[{"type":"EXPLOIT","url":"http://packetstormsecurity.com/files/168743/pfSense-pfBlockerNG-2.1.4_26-Shell-Upload.html"},{"type":"WEB","url":"http://packetstormsecurity.com/files/171123/pfBlockerNG-2.1.4_26-Remote-Code-Execution.html"},{"type":"ADVISORY","url":"https://docs.netgate.com/pfsense/en/latest/packages/pfblocker.html"},{"type":"WEB","url":"https://github.com/pfsense/FreeBSD-ports/pull/1169"},{"type":"WEB","url":"https://github.com/pfsense/FreeBSD-ports/pull/1169/commits/071bdcf2d918c3e51cde11cf81fbd9b6f0379d7e"},{"type":"EXPLOIT","url":"https://www.ihteam.net/advisory/pfblockerng-unauth-rce-vulnerability/"},{"type":"EXPLOIT","url":"http://packetstormsecurity.com/files/168743/pfSense-pfBlockerNG-2.1.4_26-Shell-Upload.html"},{"type":"WEB","url":"http://packetstormsecurity.com/files/171123/pfBlockerNG-2.1.4_26-Remote-Code-Execution.html"},{"type":"ADVISORY","url":"https://docs.netgate.com/pfsense/en/latest/packages/pfblocker.html"},{"type":"WEB","url":"https://github.com/pfsense/FreeBSD-ports/pull/1169"},{"type":"WEB","url":"https://github.com/pfsense/FreeBSD-ports/pull/1169/commits/071bdcf2d918c3e51cde11cf81fbd9b6f0379d7e"},{"type":"EXPLOIT","url":"https://www.ihteam.net/advisory/pfblockerng-unauth-rce-vulnerability/"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-06-17T04:46:21.937"}}