Brand profile · models not graded yet

Is pfSense (Netgate) Safe?

pfSense is firewall software from Netgate, a private Austin, Texas company. Security advisories, CVE history and how updates work, explained.

Last reviewed: October 2026 · ismyroutersafe.com

Ownership & FCC Status
Owner
Rubicon Communications, LLC dba Netgate (Austin, Texas, private)
FCC Status
Not on the Covered List; whether the 2026 router rule applies to its appliances is not determined
Ban Status
Not banned. Not named on the FCC Covered List
Manufacturing
Not confirmed
Models graded
Not yet

Security Verdict

Netgate is a privately held company in Austin, Texas, that develops pfSense firewall software and sells appliances that run it. It publishes detailed security advisories going back to 2014, and most recent pfSense vulnerabilities require an authenticated administrator. None are on CISA's exploited list, though a 2024 FBI/NSA advisory listed an older flaw in the pfBlockerNG add-on as used by a China-linked botnet. Updates are not installed automatically, so an administrator has to apply them.

Bottom line: pfSense has a transparent advisory record and no actively exploited flaws on CISA's list. It is safe only if an administrator applies updates and limits admin access.

Rio Router
From the team behind this checker
Weighing up Netgate? See the router that scores an A on this same method.
  • SecureRooms. Smart devices live apart from your computers.
  • You approve every new device before it joins.
  • Rio VPN built in. First year included.
  • Set up in about 10 minutes from the app.
See Rio Router →
$199.99 · 1 year of VPN included, then $7.99/mo · 30-day returns · 1-year warranty. Rio builds this site, and its router is graded by the same method as every other.

Corporate Ownership Structure

Rubicon Communications, LLC, doing business as Netgate, is a private company in Austin, Texas, founded in 2004 by Jim and Jamie Thompson. It describes itself as woman-owned and woman-run (51%). No state links were found.

Key Risk Factors

Updates must be applied by hand
pfSense checks for updates and notifies, but an administrator must confirm the install under System > Update. Unattended firewalls can fall behind.
Add-on package used by a botnet
A September 2024 FBI, Cyber National Mission Force and NSA advisory on the China-linked Flax Typhoon botnet listed CVE-2022-31814, a command injection flaw in the pfBlockerNG package through 2.1.4_26, among exploited vulnerabilities.
Critical-rated flaws in 2026
CVE-2025-69691 (CVSS 9.9) and CVE-2025-69690 (CVSS 9.1) were published in May 2026. Netgate disputes CVE-2025-69691, saying it requires admin access and works as designed.
Detailed public security advisories
Netgate publishes advisories at docs.netgate.com going back to 2014, most recently in September 2026.
No flaws on CISA's exploited list
No Netgate or pfSense vulnerability is in the CISA Known Exploited Vulnerabilities catalog as of October 2026.

Known CVEs - Netgate Routers

The following vulnerabilities from the NIST National Vulnerability Database affect Netgate router models. This is a representative sample; the full CVE list may be longer.

CVE-2025-69691 Critical (CVSS 9.9)
Code execution through XMLRPC in pfSense CE 2.8.0, disputed by Netgate as admin-only and by design.
CVE-2025-69690 Critical (CVSS 9.1)
Abuse of the pfSense CE 2.7.2 module installer with a crafted backup file.
CVE-2024-54780 High (CVSS 8.8)
Authenticated command injection in the OpenVPN dashboard widget, fixed in pfSense CE 2.8.0.
CVE-2026-97730 High (CVSS 8.5)
Authenticated local file inclusion in the dashboard, fixed in pfSense Plus 26.07 and CE 2.9.0.

Frequently Asked Questions

pfSense has a strong disclosure record: Netgate publishes detailed advisories, and none of its vulnerabilities are on CISA's exploited list. Most recent flaws require an authenticated administrator. The main risk is an unpatched box, because updates are not installed automatically.

Netgate, the trade name of Rubicon Communications, LLC, a privately held company in Austin, Texas, founded in 2004 by Jim and Jamie Thompson. It develops pfSense CE (open source) and pfSense Plus (commercial, preinstalled on Netgate appliances). Netgate describes itself as woman-owned.

No. pfSense checks for updates and notifies you, but an administrator must confirm the update under System > Update. Per Wikipedia, only the current and previous versions of CE and Plus are supported.

Netgate is not on the FCC Covered List and holds no Conditional Approval. Whether its appliances count as foreign-produced or consumer-grade under the March 2026 router rule is not determined. pfSense CE installed on your own hardware is software, not a covered device.

Netgate says its appliances are built, configured, tested and shipped by Netgate, but it does not state the country of manufacture or assembly. This is not publicly confirmed.

Sources

Facts on this page come from these sources (publish date, or the date we checked the page).

CHECK YOUR SPECIFIC MODEL

Get your router's full security report

Check any specific model for CVEs, FCC status, security capabilities, and your personalized action plan.

Check a Router → Top 10 Safe Routers
Most home routers have hidden risks. Rio Router is the only one we rate A. See why →