pfSense pfBlockerNG through 2.1.4_26 is susceptible to OS command injection via root via shell metacharacters in the HTTP Host header. NOTE: 3.x is unaffected.
id: CVE-2022-31814
info:
name: pfSense pfBlockerNG <=2.1..4_26 - OS Command Injection
author: E
...