MEDIUM
IPFire 2.21 Core Update 127 Cross-Site Scripting via ovpnmain.cgi
Published Feb 18, 2026
5.1
MEDIUMCVSS 4.0
EPSS 0.25%
Description
IPFire 2.21 Core Update 127 contains multiple cross-site scripting vulnerabilities in the ovpnmain.cgi script that allow attackers to inject malicious scripts through VPN configuration parameters. Attackers can submit POST requests with script payloads in parameters like VPN_IP, DMTU, ccdname, ccdsubnet, DOVPN_SUBNET, DHCP_DOMAIN, DHCP_DNS, DHCP_WINS, ROUTES_PUSH, FRAGMENT, KEEPALIVE_1, and KEEPALIVE_2 to execute arbitrary JavaScript in administrator browsers.
Affected products
-
- Version IPFire 2.21 - Core Update 127StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- https://downloads.ipfire.org/releases/ipfire-2.x/2.21-core127/ipfire-2.21.x86_64-full-core127.iso patchProduct
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-19632 Advisory
- https://www.exploit-db.com/exploits/46344 exploitThird Party AdvisoryVDB Entry
- https://www.ipfire.org product
- https://www.vulncheck.com/advisories/ipfire-core-update-cross-site-scripting-via-ovpnma third-party-advisoryBroken LinkThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://downloads.ipfire.org/releases/ipfire-2.x/2.21-core127/ipfire-2.21.x86_64-full-core127.iso | patchProduct | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-19632 | Advisory | |
| https://www.exploit-db.com/exploits/46344 | exploitThird Party AdvisoryVDB Entry | |
| https://www.ipfire.org | product | |
| https://www.vulncheck.com/advisories/ipfire-core-update-cross-site-scripting-via-ovpnma | third-party-advisoryBroken LinkThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Feb 18, 2026
Updated May 24, 2026
Reserved Feb 18, 2026
Link CVE-2019-25398
CISA Vulnrichment
Updated Feb 19, 2026
ENISA EUVD
EUVD-2019-19632 Assigner VulnCheck
Published Feb 18, 2026
Updated May 24, 2026
Exploited since n/a
Link EUVD-2019-19632