{"id":"CVE-2025-34311","title":"IPFire versions prior to 2.29 (Core Update 198) contain a command injection vulnerability that allows an authenticated attacker to execute arbitrary commands as the user 'nobody' via multiple parameters when creating a Proxy report","summary":"IPFire versions prior to 2.29 (Core Update 198) contain a command injection vulnerability that allows an authenticated attacker to execute arbitrary commands as the user 'nobody' via multiple parameters when creating a Proxy report. When…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-78"],"vendor":"ipfire","product":"ipfire","affected":["ipfire < 2.29","ipfire = 2.29"],"patched":["ipfire 2.29"],"published":"2025-10-28","updated":"2026-09-26","sourceUpdated":"2026-09-26T00:10:00.127","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-34311","references":[{"url":"https://bugzilla.ipfire.org/show_bug.cgi?id=13886","label":"disclosure@vulncheck.com"},{"url":"https://www.ipfire.org/blog/ipfire-2-29-core-update-198-released","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/ipfire-command-injection-via-proxy-report-creation","label":"disclosure@vulncheck.com"}],"tags":["nvd"],"epss":0.13784,"epssPercentile":0.96383,"ingestedAt":"2026-09-26T00:22:39.963Z","slug":"CVE-2025-34311","body":"## Overview\n\nIPFire versions prior to 2.29 (Core Update 198) contain a command injection vulnerability that allows an authenticated attacker to execute arbitrary commands as the user 'nobody' via multiple parameters when creating a Proxy report. When a user creates a Proxy report the application issues an HTTP POST to /cgi-bin/logs.cgi/calamaris.dat and reads the values of DAY_BEGIN, MONTH_BEGIN, YEAR_BEGIN, DAY_END, MONTH_END, YEAR_END, NUM_DOMAINS, PERF_INTERVAL, NUM_CONTENT, HIST_LEVEL, NUM_HOSTS, NUM_URLS, and BYTE_UNIT, which are interpolated directly into the shell invocation of the mkreport helper. Because these parameters are never sanitized for improper characters or constructs, a crafted POST can inject shell metacharacters into one or more fields, causing arbitrary commands to run with the privileges of the 'nobody' user.\n\n## Affected\n\n- `ipfire < 2.29`\n- `ipfire = 2.29`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `ipfire 2.29`","depth":"twilight","depthScore":51,"depthScoreParts":{"impact":48.4,"likelihood":2.8,"exploitation":0,"ransomware":0},"changes":[]}