CVE-2025-50975

IPFire 2.29 web-based firewall interface (firewall.cgi) fails to sanitize several rule parameters such as PROT, SRC_PORT, TGT_PORT, dnatport, key, ruleremark, src_addr, std_net_tgt, and tgt_addr, allowing an authenticated administrator to inject persistent JavaScript. This stored XSS payload is executed whenever another admin views the firewall rules page, enabling session hijacking, unauthorized actions within the interface, or further internal pivoting. Exploitation requires only high-privilege GUI access, and the complexity of the attack is low.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ipfire:ipfire:2.29:-:*:*:*:*:*:*

History

09 Sep 2025, 18:55

Type Values Removed Values Added
CPE cpe:2.3:a:ipfire:ipfire:2.29:-:*:*:*:*:*:*
First Time Ipfire ipfire
Ipfire
References () https://github.com/4rdr/proofs/blob/main/info/IPFire-2.29-Stored-XSS-via-Firewall.md - () https://github.com/4rdr/proofs/blob/main/info/IPFire-2.29-Stored-XSS-via-Firewall.md - Exploit, Third Party Advisory

27 Aug 2025, 15:15

Type Values Removed Values Added
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
Summary
  • (es) La interfaz del firewall web IPFire 2.29 (firewall.cgi) no depura varios parámetros de reglas, como PROT, SRC_PORT, TGT_PORT, dnatport, key, ruleremark, src_addr, std_net_tgt y tgt_addr, lo que permite que un administrador autenticado inyecte JavaScript persistente. Este payload XSS almacenado se ejecuta cada vez que otro administrador accede a la página de reglas del firewall, lo que permite el secuestro de sesiones, acciones no autorizadas dentro de la interfaz o un mayor pivoteo interno. La explotación solo requiere acceso a la interfaz gráfica con privilegios altos, y la complejidad del ataque es baja.
References () https://github.com/4rdr/proofs/blob/main/info/IPFire-2.29-Stored-XSS-via-Firewall.md - () https://github.com/4rdr/proofs/blob/main/info/IPFire-2.29-Stored-XSS-via-Firewall.md -

26 Aug 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-26 19:15

Updated : 2025-09-09 18:55


NVD link : CVE-2025-50975

Mitre link : CVE-2025-50975

CVE.ORG link : CVE-2025-50975


JSON object : View

Products Affected

ipfire

  • ipfire
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')