PT-2026-20831 · Cdome+1 · Comodo Dome Firewall+1

Ozer Goker

·

Published

2026-02-19

·

Updated

2026-02-19

·

CVE-2019-25428

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Comodo Dome Firewall version 2.7.0
Description Reflected cross-site scripting occurs in the "openvpn users" endpoint. This allows attackers to execute arbitrary JavaScript in users' browsers by submitting crafted POST requests containing script payloads in the username, remotenets, explicitroutes, static ip, custom dns, or custom domain parameters.
Recommendations As a temporary workaround, restrict access to the "openvpn users" endpoint or avoid using the username, remotenets, explicitroutes, static ip, custom dns, and custom domain parameters until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2019-25428

Affected Products

Comodo Dome Firewall
Dome Firewall