CVE-2025-34174 Details
Description
In pfSense CE /usr/local/www/status_traffic_totals.php, the value of the start-day parameter is not ensured to be a numeric value or sanitized of HTML-related characters/strings before being directly displayed in the input box. This value can be saved as the default value to be displayed to all users when visiting the Status Traffic Totals page, resulting in stored cross-site scripting. The attacker must be authenticated with at least "WebCfg - Status: Traffic Totals" permissions.
A stored cross-site scripting vulnerability has been identified in the pfSense CE Status Traffic Totals package. The issue arises in the file '/usr/local/www/status_traffic_totals.php', where the 'start-day' parameter is not properly validated or sanitized before being displayed. This unsanitized value can be saved as a default, leading to cross-site scripting that is stored and executed when users visit the Status Traffic Totals page. To exploit this vulnerability, an attacker must be authenticated and have 'WebCfg - Status: Traffic Totals' permissions.
Users can update to pfSense CE versions 2.8.1, 2.8.0, or the Plus versions 25.07.1 or 25.07 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Sep 10, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| pfsense pfsense | < 2.8.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 10, 2025 | Initial Analysis | [email protected] |
| Sep 17, 2025 | CVE Modified | [email protected] |
| Sep 9, 2025 | New CVE Received | [email protected] |