Back

CRITICAL

FreeNAS < 0.7.2 rev 5543 exec_raw.php Arbitrary Command Execution

Published Aug 20, 2025

Description

FreeNAS 0.7.2 prior to revision 5543 includes an unauthenticated command‐execution backdoor in its web interface. The exec_raw.php script exposes a cmd parameter that is passed directly to the underlying shell without sanitation.

Affected products

Remediation

No remediation recorded yet.

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Aug 20, 2025
Updated May 15, 2026
Reserved Aug 19, 2025
CISA Vulnrichment
Updated Aug 22, 2025
NVD
Status Deferred
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date n/a