Back to search
CVE-2010-20059
Published: Aug 20, 2025
Modified: May 15, 2026
PUBLISHED
Description
FreeNAS 0.7.2 prior to revision 5543 includes an unauthenticated command‐execution backdoor in its web interface. The exec_raw.php script exposes a cmd parameter that is passed directly to the underlying shell without sanitation.
| Vendor | Product | Versions |
|---|---|---|
iXsystems | FreeNAS | affected 0 - < 0.7.2 rev 5543 |
Weaknesses (CWE)
References
https://github.com/freenas
product
https://www.tenable.com/plugins/nnm/5714
third-party-advisory
https://www.vulncheck.com/advisories/freenas-arbitrary-command-execution
third-party-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now