· 15 min easy Other Sense
HTB: Sense
A plaintext credential file and default password on a pfSense 2.1.3 appliance lead to authenticated command injection (CVE-2016-10709) running as root. Network appliances run as root by design, making management interface access the only real security boundary.
#htb
#pfsense
#openbsd
#command-injection +1