IPFire 2.29 web-based firewall interface (firewall.cgi) fails to sanitize several rule parameters such as PROT, SRC_PORT, TGT_PORT, dnatport, key, ruleremark, src_addr, std_net_tgt, and tgt_addr, allowing an authenticated administrator to inject persistent JavaScript. This stored XSS payload is executed whenever another admin views the firewall rules page, enabling session hijacking, unauthorized actions within the interface, or further internal pivoting. Exploitation requires only high-privilege GUI access, and the complexity of the attack is low.
References
Link | Resource |
---|---|
https://github.com/4rdr/proofs/blob/main/info/IPFire-2.29-Stored-XSS-via-Firewall.md | Exploit Third Party Advisory |
https://github.com/4rdr/proofs/blob/main/info/IPFire-2.29-Stored-XSS-via-Firewall.md | Exploit Third Party Advisory |
Configurations
History
09 Sep 2025, 18:55
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:ipfire:ipfire:2.29:-:*:*:*:*:*:* | |
First Time |
Ipfire ipfire
Ipfire |
|
References | () https://github.com/4rdr/proofs/blob/main/info/IPFire-2.29-Stored-XSS-via-Firewall.md - Exploit, Third Party Advisory |
27 Aug 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-79 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
Summary |
|
|
References | () https://github.com/4rdr/proofs/blob/main/info/IPFire-2.29-Stored-XSS-via-Firewall.md - |
26 Aug 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-08-26 19:15
Updated : 2025-09-09 18:55
NVD link : CVE-2025-50975
Mitre link : CVE-2025-50975
CVE.ORG link : CVE-2025-50975
JSON object : View
Products Affected
ipfire
- ipfire
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')