Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
5.1

Comodo Dome Firewall 2.7.0 Allows Malicious Script Injection

CVE-2019-25426
Summary

Comodo Dome Firewall's dnsmasq endpoint can be tricked into executing malicious scripts in users' browsers. This can happen if an attacker sends a specially crafted request to the firewall. Users should update to a patched version of the software to protect against this type of attack.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
comodo dome_firewall <= 2.7.0 –
Original title
Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted input to the dnsmasq endpoint. Attackers c...
Original description
Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted input to the dnsmasq endpoint. Attackers can send POST requests with script payloads in the TRANSPARENT_SOURCE_BYPASS or TRANSPARENT_DESTINATION_BYPASS parameters to execute arbitrary JavaScript in users' browsers.
nvd CVSS3.1 6.1
nvd CVSS4.0 5.1
Vulnerability type
CWE-79 Cross-site Scripting (XSS)
Published: 19 Feb 2026 · Updated: 11 Mar 2026 · First seen: 6 Mar 2026