- Web panel allows root code execution on the device (every XSS is full RCE!)
- Everything runs as root
- No ASLR or other hardening flags because FreeBSD
- Lots of XSS and CSRF opportunities (probably got better with the new UI)
- Did not replace SSL certificate after Heartbleed (on packages.pfsense.org!)
- No package signing, either (not sure if this is still true with pkgng)
- Did not even have SSL on packages.pfsense.org until one or two years ago
I'm also missing the fq_codel queueing discipline on my home network (prevents bufferbloat).
I still use it since it's awesome, but I hope their security posture has improved since.
Most of the commercial vendors are even worse, but still.