PT-2026-8373 · Smoothwall · Smoothwall Express
Ozer Goker
·
Published
2026-02-16
·
Updated
2026-02-16
·
CVE-2019-25390
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Smoothwall Express version 3.1-SP4-polar-x86 64-update9
Description
The software contains multiple reflected cross-site scripting issues within the 'interfaces.cgi' script. These issues allow attackers to inject malicious scripts through several parameters, including
GREEN ADDRESS, GREEN NETMASK, RED DHCP HOSTNAME, RED ADDRESS, DNS1 OVERRIDE, DNS2 OVERRIDE, RED MAC, RED NETMASK, DEFAULT GATEWAY, DNS1, and DNS2. Attackers can create POST requests to the ''/interfaces.cgi'' endpoint with script payloads in these parameters, leading to the execution of arbitrary JavaScript within authenticated administrator sessions.Recommendations
For Smoothwall Express version 3.1-SP4-polar-x86 64-update9, sanitize all input to the 'interfaces.cgi' script, specifically the
GREEN ADDRESS, GREEN NETMASK, RED DHCP HOSTNAME, RED ADDRESS, DNS1 OVERRIDE, DNS2 OVERRIDE, RED MAC, RED NETMASK, DEFAULT GATEWAY, DNS1, and DNS2 parameters, to prevent the injection of malicious scripts.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Smoothwall Express