CRITICAL
FreeNAS < 0.7.2 rev 5543 exec_raw.php Arbitrary Command Execution
Published Aug 20, 2025
9.3
CRITICALCVSS 4.0
EPSS 1.02%
Description
FreeNAS 0.7.2 prior to revision 5543 includes an unauthenticated command‐execution backdoor in its web interface. The exec_raw.php script exposes a cmd parameter that is passed directly to the underlying shell without sanitation.
Affected products
-
- Version 0StatusaffectedConstraints<0.7.2 rev 5543
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (8)
- https://github.com/freenas product
- https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/multi/http/freenas_exec_raw.rb exploit
- https://sourceforge.net/projects/freenas/ product
- https://web.archive.org/web/20101218143110/http://sourceforge.net/projects/freenas/files//stable/0.7.2/NOTES%200.7.2.5543.txt/view vendor-advisorypatch
- https://www.exploit-db.com/exploits/16313 exploit
- https://www.tenable.com/plugins/nnm/5714 third-party-advisory
- https://www.truenas.com/freenas/ product
- https://www.vulncheck.com/advisories/freenas-arbitrary-command-execution third-party-advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Aug 20, 2025
Updated May 15, 2026
Reserved Aug 19, 2025
Link CVE-2010-20059
CISA Vulnrichment
Updated Aug 22, 2025