Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the MACHINES parameter. Attackers can craft requests to the timedaccess.cgi endpoint with script payloads in the MACHINES parameter to execute arbitrary JavaScript in users' browsers.
Metrics
Affected Vendors & Products
References
History
Tue, 17 Feb 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 17 Feb 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Smoothwall smoothwall Express
|
|
| Vendors & Products |
Smoothwall smoothwall Express
|
Mon, 16 Feb 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the MACHINES parameter. Attackers can craft requests to the timedaccess.cgi endpoint with script payloads in the MACHINES parameter to execute arbitrary JavaScript in users' browsers. | |
| Title | Smoothwall Express 3.1 'timedaccess.cgi' Cross-Site Scripting | |
| First Time appeared |
Smoothwall
Smoothwall smoothwall |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:smoothwall:smoothwall:3.1:*:*:*:*:*:*:* | |
| Vendors & Products |
Smoothwall
Smoothwall smoothwall |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-02-16T17:05:03.304Z
Updated: 2026-02-17T14:58:09.041Z
Reserved: 2026-02-16T16:32:30.518Z
Link: CVE-2019-25389
Updated: 2026-02-17T14:58:00.511Z
Status : Received
Published: 2026-02-16T18:19:43.643
Modified: 2026-02-16T18:19:43.643
Link: CVE-2019-25389
No data.
ReportizFlow