From nmap, there are http and https service.

Local Picture

This is the https web page, which is a PfSense firewall. (http redirects to https automatically)

Local Picture

This is the result from gobuster.

Local Picture

Take a look at changelog.txt, it seems that there is still a vulnerability hasn’t been patched.

Local Picture

From system-users.txt, we got the idea that the credential is Rohit:pfsense.

Local Picture

We successfully login.

Local Picture

I tried to use module unix/http/pfsense_graph_injection_exec in msf, and got root permission.

Local Picture