S4E just found a medium-severity finding from cookies without secure attribute security misconfiguration scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 21, 2025

CVE-2022-40624 Scanner

CVE-2022-40624 Scanner - OS Command Injection vulnerability in pfSense pfBlockerNG

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.9k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
2
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-40624
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

pfSense pfBlockerNG through 2.1.4_27 allows remote attackers to execute arbitrary OS commands as root via the HTTP Host header, a different vulnerability than CVE-2022-31814.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

pfSense pfBlockerNG is a widely used firewall and network protection tool integrated with the pfSense platform. It is designed to enhance network security by blocking unwanted traffic, managing DNS blocking, and controlling access to specific domains and IP addresses. pfSense pfBlockerNG is frequently used by organizations and individuals to strengthen their cybersecurity defenses.

This vulnerability allows remote attackers to execute arbitrary OS commands via the HTTP Host header in pfSense pfBlockerNG versions through 2.1.4_27. The improper handling of input in the Host header results in command injection, providing attackers with root-level access to the system. This makes the vulnerability critical as it allows complete control over the affected systems.

Technical details reveal that the flaw lies in the lack of proper sanitization of the HTTP Host header. Attackers can craft malicious headers to inject arbitrary commands, which are then executed on the system with root privileges. Exploiting this vulnerability requires minimal effort and no prior authentication.

If exploited, this vulnerability can lead to the full compromise of the system, including unauthorized access to sensitive data, manipulation of firewall rules, and deployment of additional malware. The severity of the vulnerability makes it essential for users to apply patches immediately to avoid catastrophic security breaches.

REFERENCES

Solution Advice
  • Update to the latest version of pfSense pfBlockerNG where the vulnerability is patched.
  • Implement input validation for HTTP headers to prevent malicious command injection.
  • Restrict access to administrative interfaces to trusted networks only.
  • Regularly monitor system logs for suspicious activities involving HTTP headers.
  • Enable intrusion detection and prevention systems to block potential exploitation attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.