S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-31814 Scanner

CVE-2022-31814 scanner - OS Command Injection vulnerability in pfSense pfBlockerNG

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.5k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-31814
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the HTTP Host header. NOTE: 3.x is unaffected.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
pfblockerngby netgate
2.1.4_26
Updated Aug 22, 2026View on NVD →
Detail

pfSense pfBlockerNG is a widely-used package used for enhancing the firewall capability of pfSense open-source software. This tool allows administrators to filter traffic at both the DNS and IP level, blocking malicious networks, domains, and hosts from accessing the network. PfBlockerNG's granular control and precise filtering make it a valuable tool for network administrators seeking to secure their network and prevent unauthorized access.

However, the security of pfBlockerNG has recently come into question with the discovery of CVE-2022-31814. This vulnerability, present in version 2.1.4_26, enables remote attackers to execute arbitrary OS commands as root by exploiting shell metacharacters in the HTTP host header. This vulnerability can lead to a significant compromise of network security, as attackers can gain elevated privileges and have unfettered access to the system.

When exploited, CVE-2022-31814 can result in a complete takeover of the pfBlockerNG system, putting the entire network at risk. As a result, attackers can successfully carry out cyberattacks such as data theft or ransomware, resulting in loss of data and financial damage for organizations. Therefore, this vulnerability poses a significant threat to network security and requires immediate attention and remedial action.

In conclusion, it's vital for network administrators to be aware of and take steps to secure their digital assets against vulnerabilities such as CVE-2022-31814. With the pro features of s4e.io platform, administrators can easily and quickly learn about vulnerabilities in their digital assets and take appropriate measures to mitigate risks. By keeping updated on the latest network and cybersecurity trends, organizations can ensure the protection of their networks and data.

 

REFERENCES

Solution Advice

To protect against this vulnerability, network administrators can take the following precautions:

  • Update to the latest version of pfBlockerNG as it is unaffected by this vulnerability.
  • Restrict access to the firewall interface such that only secure, authorized network segments can establish a connection.
  • Set firewall rules to block HTTP requests and restrict access to management interfaces.
  • Activate intrusion detection/alerting mechanisms to notify administrators of any attempted breaches or malicious activity.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.