# CVE-2025-34116

## Summary

- **CVE ID:** CVE-2025-34116
- **Severity:** HIGH
- **CVSS Score:** 8.7 (CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)
- **CWE:** CWE-78, CWE-20, CWE-306
- **Published:** Jul 15, 2025
- **Last Modified:** May 15, 2026

## Description

A remote command execution vulnerability exists in IPFire before version 2.19 Core Update 101 via the 'proxy.cgi' CGI interface. An authenticated attacker can inject arbitrary shell commands through crafted values in the NCSA user creation form fields, leading to command execution with web server privileges.

## Affected Products

- IPFire Project — IPFire (*)
- IPFire Project — IPFire (0)

## References

- [CNA](https://www.ipfire.org/news/ipfire-2-19-core-update-101-released)
- [CNA](https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/linux/http/ipfire_proxy_exec.rb)
- [CNA](https://www.exploit-db.com/exploits/39765)
- [CNA](https://www.asafety.fr/en/vuln-exploit-poc/xss-rce-ipfire-2-19-core-update-101-remote-command-execution/)
- [CNA](https://bugzilla.ipfire.org/show_bug.cgi?id=11087)
- [CNA](https://www.vulncheck.com/advisories/ipfire-authenticated-rce)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 1.67%
- **EPSS Percentile:** 75.3

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._