Metrics
Affected Vendors & Products
Fri, 20 Feb 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:o:smoothwall:smoothwall_express:3.1:sp4:*:*:-:*:*:* |
Tue, 17 Feb 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
ssvc
|
Tue, 17 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 17 Feb 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Smoothwall smoothwall Express
|
|
| Vendors & Products |
Smoothwall smoothwall Express
|
Mon, 16 Feb 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple reflected cross-site scripting vulnerabilities in the dhcp.cgi script that allow attackers to inject malicious scripts through multiple parameters. Attackers can submit POST requests to dhcp.cgi with script payloads in parameters such as BOOT_SERVER, BOOT_FILE, BOOT_ROOT, START_ADDR, END_ADDR, DNS1, DNS2, NTP1, NTP2, WINS1, WINS2, DEFAULT_LEASE_TIME, MAX_LEASE_TIME, DOMAIN_NAME, NIS_DOMAIN, NIS1, NIS2, STATIC_HOST, STATIC_DESC, STATIC_MAC, and STATIC_IP to execute arbitrary JavaScript in user browsers. | |
| Title | Smoothwall Express 3.1 'dhcp.cgi' Cross-Site Scripting | |
| First Time appeared |
Smoothwall
Smoothwall smoothwall |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:smoothwall:smoothwall:3.1:*:*:*:*:*:*:* | |
| Vendors & Products |
Smoothwall
Smoothwall smoothwall |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-02-16T17:04:54.998Z
Updated: 2026-02-17T16:48:57.484Z
Reserved: 2026-02-16T16:27:08.866Z
Link: CVE-2019-25380
Updated: 2026-02-17T14:49:41.776Z
Status : Analyzed
Published: 2026-02-16T18:19:42.153
Modified: 2026-02-20T16:25:48.847
Link: CVE-2019-25380
No data.