Netgate pfSense CE 2.8.0 allows code execution in the XMLRPC API via pfsense.exec_php. NOTE: the Supplier disputes this because the API call is only available to admins and they are intentionally allowed to execute PHP code.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2025-69691 affects Netgate pfSense CE 2.8.0 and exposes a critical vulnerability in the XMLRPC API endpoint through the pfsense.exec_php function, which permits arbitrary PHP code execution with a CVSS score of 9.9. While Netgate disputes the severity claim by noting that API access is restricted to administrative users who have intentional PHP execution capabilities, the vulnerability remains significant because administrative credentials can be compromised through phishing, credential theft, or lateral movement attacks—transforming a "by design" feature into an active exploitation vector. Organizations running pfSense instances are affected if they expose the XMLRPC API to untrusted networks or maintain weak administrative access controls, making this a critical concern for network infrastructure security.
Casky's threat detection capabilities excel in this scenario by mapping administrative privilege abuse and API misuse patterns across the security skills library. Although this CVE itself maps to zero specific MITRE ATT&CK techniques in standard catalogs, practitioners using Casky would identify attack patterns associated with CWE-284 (Improper Access Control) and CWE-915 (Improperly Controlled Modification of Dynamically-Determined Object Attributes) through behavioral analysis. Practitioners would detect suspicious XMLRPC API calls, unusual PHP execution requests from administrative accounts, and anomalous network traffic patterns targeting the management interface. Extended reasoning across Casky's 754 skills would surface related attack chains including Execution (T1059—Command and Scripting Interpreter), Persistence (T1098—Account Manipulation), and Lateral Movement patterns, enabling defenders to correlate compromise indicators and prioritize remediation of exposed pfSense instances before attackers exploit administrative access pathways.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2025-69691. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation