| Check Point Reference: | CPAI-2025-15311 |
| Date Published: | 27 Apr 2026 |
| Severity: | Medium |
| Last Updated: | Monday 27 April, 2026 |
| Source: | |
| Industry Reference: | CVE-2025-34309 |
| Protection Provided by: |
Security Gateway |
| Who is Vulnerable? | IPFire prior to 2.29 IPFire 2.29 core update183 IPFire 2.29 core update184 IPFire 2.29 core update185 IPFire 2.29 core update186 IPFire 2.29 core update187 IPFire 2.29 core update188 IPFire 2.29 core update189 IPFire 2.29 core update190 IPFire 2.29 core update191 IPFire 2.29 core update192 IPFire 2.29 core update193 IPFire 2.29 core update194 IPFire 2.29 core update195 IPFire 2.29 core update196 IPFire 2.29 core update197 |
| Vulnerability Description | A cross-site scripting vulnerability in IPFire allows an authenticated attacker to inject arbitrary JavaScript code through the SERVICE, LOGIN, and PASSWORD parameters when creating or editing a Dynamic DNS host. This vulnerability affects IPFire versions prior to 2.29 (Core Update 198). |
This protection detects attempts to exploit this vulnerability.
In order for the protection to be activated, update your Security Gateway product to the latest IPS update. For information on how to update IPS, go to SBP-2006-05, click on Protection tab and select the version of your choice.
This protection's log will contain the following information:
Attack Name: Application Servers Protection Violation.
Attack Information: IPFire Cross-Site Scripting (CVE-2025-34309)