« Volver al listado

CVE-2026-26352

Estado: AnalizadaMedia (5.1)—

Smoothwall Express versions prior to 3.1 Update 13 contain a stored cross-site scripting vulnerability in the /cgi-bin/vpnmain.cgi script due to improper sanitation of the VPN_IP parameter. Authenticated attackers can inject arbitrary JavaScript through VPN configuration settings that executes when the affected page is viewed by other users.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-26352",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-26352",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-03-30T18:08:28.119085Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "disclosure@vulncheck.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 5.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.3
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "disclosure@vulncheck.com",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 5.1,
          "Automatable": "NOT_DEFINED",
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
          "exploitMaturity": "NOT_DEFINED",
          "providerUrgency": "NOT_DEFINED",
          "userInteraction": "PASSIVE",
          "attackComplexity": "LOW",
          "attackRequirements": "NONE",
          "privilegesRequired": "LOW",
          "subIntegrityImpact": "LOW",
          "vulnIntegrityImpact": "NONE",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "NONE",
          "vulnAvailabilityImpact": "NONE",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "LOW",
          "vulnConfidentialityImpact": "NONE",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "disclosure@vulncheck.com",
      "affectedData": [
        {
          "repo": "https://sourceforge.net/projects/smoothwall/",
          "vendor": "Smoothwall",
          "product": "Express",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "3.1 Update 13",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-03-30T17:16:14.363",
  "references": [
    {
      "url": "https://community.smoothwall.org/forum/viewtopic.php?t=45095",
      "tags": [
        "Product",
        "Release Notes"
      ],
      "source": "disclosure@vulncheck.com"
    },
    {
      "url": "https://www.vulncheck.com/advisories/smoothwall-express-stored-xss-in-vpnmain-cgi-via-vpn-ip-parameter",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "disclosure@vulncheck.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "disclosure@vulncheck.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Smoothwall Express versions prior to 3.1 Update 13 contain a stored cross-site scripting vulnerability in the /cgi-bin/vpnmain.cgi script due to improper sanitation of the VPN_IP parameter. Authenticated attackers can inject arbitrary JavaScript through VPN configuration settings that executes when the affected page is viewed by other users."
    },
    {
      "lang": "es",
      "value": "Smoothwall Express versiones anteriores a 3.1 Update 13 contienen una vulnerabilidad de cross-site scripting almacenado en el script /cgi-bin/vpnmain.cgi debido a una sanitización inadecuada del parámetro VPN_IP. Atacantes autenticados pueden inyectar JavaScript arbitrario a través de la configuración de VPN que se ejecuta cuando la página afectada es vista por otros usuarios."
    }
  ],
  "lastModified": "2026-06-17T10:26:08.300",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:smoothwall:smoothwall_express:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F0BC090B-12A9-4A0E-9BD2-EFA56B569432",
              "versionEndIncluding": "3.0"
            },
            {
              "criteria": "cpe:2.3:o:smoothwall:smoothwall_express:3.1:update1:*:*:-:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "714B3296-7323-4920-8832-827C697ABED8"
            },
            {
              "criteria": "cpe:2.3:o:smoothwall:smoothwall_express:3.1:update10:*:*:-:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "07EF8E3A-93A2-4A5A-A077-B692D7B4D92F"
            },
            {
              "criteria": "cpe:2.3:o:smoothwall:smoothwall_express:3.1:update11:*:*:-:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2B3D4296-EE7C-46FD-A734-419DC0BDFB7A"
            },
            {
              "criteria": "cpe:2.3:o:smoothwall:smoothwall_express:3.1:update12:*:*:-:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "230A2DC9-DE28-4D18-99B8-0567CE99969C"
            },
            {
              "criteria": "cpe:2.3:o:smoothwall:smoothwall_express:3.1:update2:*:*:-:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5F0EED85-4850-4303-9529-E45868061C90"
            },
            {
              "criteria": "cpe:2.3:o:smoothwall:smoothwall_express:3.1:update3:*:*:-:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0A0D511A-9CBB-4586-BF80-AAC12101B9E4"
            },
            {
              "criteria": "cpe:2.3:o:smoothwall:smoothwall_express:3.1:update4:*:*:-:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2999F419-BAF9-4660-8983-BB5A8374450E"
            },
            {
              "criteria": "cpe:2.3:o:smoothwall:smoothwall_express:3.1:update5:*:*:-:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "83811BB5-B833-4594-823D-C47CB8499DD0"
            },
            {
              "criteria": "cpe:2.3:o:smoothwall:smoothwall_express:3.1:update6:*:*:-:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E2A35B5F-2BFD-43D2-B0AC-EFCA7A5A8E2C"
            },
            {
              "criteria": "cpe:2.3:o:smoothwall:smoothwall_express:3.1:update7:*:*:-:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "60C265FF-2CB3-4A44-9017-451D06E2CBE4"
            },
            {
              "criteria": "cpe:2.3:o:smoothwall:smoothwall_express:3.1:update8:*:*:-:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E5DB05A8-F012-4258-82B9-B42884F88722"
            },
            {
              "criteria": "cpe:2.3:o:smoothwall:smoothwall_express:3.1:update9:*:*:-:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D5EF08B4-276D-4EE1-A079-3A2E61FED713"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "disclosure@vulncheck.com"
}