IPFire < 2.19 Core Update 101 proxy.cgi RCE
Vulnerability Description
A remote command execution vulnerability exists in IPFire before version 2.19 Core Update 101 via the 'proxy.cgi' CGI interface. An authenticated attacker can inject arbitrary shell commands through crafted values in the NCSA user creation form fields, leading to command execution with web server privileges.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-34116
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Yann Cam
References
- https://www.ipfire.org/news/ipfire-2-19-core-update-101-released
- https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/linux/http/ipfire_proxy_exec.rb
- https://www.exploit-db.com/exploits/39765
- https://www.asafety.fr/en/vuln-exploit-poc/xss-rce-ipfire-2-19-core-update-101-remote-command-execution/
- https://bugzilla.ipfire.org/show_bug.cgi?id=11087
- https://www.vulncheck.com/advisories/ipfire-authenticated-rce
Affected Vendor
IPFire Project
View all reports →