CVE-2026-78902: Crafted DNS Reply Enables XSS-to-RCE on pfSense

Summary
A flaw in pfBlockerNG on pfSense lets a crafted DNS reply trigger stored XSS when an administrator views Reports, potentially leading to root access. Netgate fixed the issue in pfBlockerNG 3.2.16_1.
Key points
- The flaw affects pfBlockerNG on pfSense when DNS Reply Logging is enabled and the package is processing DNS requests in the described configuration.
- An attacker can send a crafted DNS reply that is logged and later rendered unsafely in the pfSense web interface, enabling stored cross-site scripting.
- If an administrator views the affected Reports page, attacker-controlled JavaScript can use pfSense's command-execution page to run commands and obtain a root shell.
- The attack requires a DNS lookup from inside the network to pass through the affected resolver and an administrator to view the vulnerable report.
- Netgate released pfBlockerNG version 3.2.16_1 on July 2, 2026, within a day of receiving the report; NetSPI says it tested the fix.
Article Details
- Vulnerability Types
- Stored cross-site scripting (XSS)
- Remote code execution through the stored XSS attack chain
- Severity
- High-risk, according to NetSPI
- Exploitation Status
- reported
- Exploit Availability
- claimed_or_private
- Patch Status
- available
MITRE ATT&CK
T1059.004 · Unix ShellThe injected JavaScript submits a shell command through pfSense's command execution page using a CSRF token scraped from that page.T1059.007 · JavaScriptA crafted DNS reply is logged and later rendered without escaping, causing attacker-supplied JavaScript to run when an administrator views the Stats tab.T1105 · Ingress Tool TransferThe submitted command downloads a reverse shell script onto the appliance before running it.
CVE
Vendors
Products
pfBlockerNGEarlier this year, NetSPI discovered a series of flaws in the pfBlockerNG package.pfSensepfBlockerNG is used by pfSense firewalls to expand its preventative controls and provides DNS-based blocking and IP-based firewall rules fed by threat intelligence lists.UnboundThe package supports an Unbound Python mode, which is the recommended setup for regex blocking, TLD allow lists, and appliances configured with large blocklists and limited RAM.