Executive brief
A vulnerability exists in the Suricata security package for pfSense firewalls, which are used to monitor and protect network traffic. An authenticated user with specific permissions can use a flaw in the IP reputation management interface to determine if specific files exist on the underlying system. While the attacker cannot read the contents of these files, the ability to map out the file system can be used to gather intelligence for more complex subsequent attacks.
Technical details
A directory traversal vulnerability exists in the /suricata/suricata_ip_reputation.php component of the pfSense Suricata package. The 'iplist' parameter does not properly sanitize directory traversal sequences (e.g., ../) before using the value in a file existence check. While the application does not return the file contents, the response indicates whether a file exists at the specified path, allowing an authenticated attacker with 'WebCfg - Services: suricata package' permissions to enumerate files on the local filesystem. The issue is addressed in pfSense CE 2.8.0, pfSense Plus 25.07, and Suricata package version 7.0.8_3 or higher.
Affected products
- Netgate pfSense CE up to (excluding) 2.8.0
- Netgate pfSense Plus up to (excluding) 25.07.1
- Netgate Suricata package for pfSense <= 7.0.8_2
Timeline
- 2025-09-09: disclosed
- 2025-09-09: patched
- 2025-09-09: advisory