Description
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in TR7 Cyber ​​Defense Inc. Web Application Firewall allows DOM-Based XSS.

This issue affects Web Application Firewall: from v1.0.42.239 before v1.4.0.117.
Published: 2026-07-02
Score: 4.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is a DOM‑Based Cross‑Site Scripting vulnerability in TR7 Cyber Defense Inc.'s Web Application Firewall (WAF‑ASP). The firewall does not neutralize user input when it builds client‑side content, allowing an attacker to inject malicious JavaScript that is executed within the victim’s browser. The classification as CWE‑79 suggests the issue stems from insufficient input sanitization. There is no evidence of additional impact beyond the execution of injected script.

Affected Systems

The vulnerability exists in all releases of TR7 Cyber Defense Inc.'s WAF‑ASP from firmware version 1.0.42.239 up to, but not including, version 1.4.0.117. Any user running a firmware revision within this range is affected.

Risk and Exploitability

With a CVSS score of 4.6 the weakness is rated low‑to‑moderate severity, and an EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The flaw is not yet listed in the CISA KEV catalog. The likely attack vector involves a malicious web page or crafted input that passes through the firewall and reaches the victim’s browser; no publicly available exploit is known, so exploitation likelihood is inferred from the provided metrics.

Generated by OpenCVE AI on July 21, 2026 at 11:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the WAF‑ASP to firmware version 1.4.0.117 or later to eliminate the XSS flaw.
  • If an immediate upgrade is not possible, enforce strict input validation and sanitization on all data before it is incorporated into client‑side contexts, ensuring that scripts cannot be injected via the browser.
  • Conduct an internal XSS assessment or penetration test after implementing the remediation to verify that the vulnerability has been fully mitigated.

Generated by OpenCVE AI on July 21, 2026 at 11:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 02 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in TR7 Cyber ​​Defense Inc. Web Application Firewall allows DOM-Based XSS. This issue affects Web Application Firewall: from v1.0.42.239 before v1.4.0.117.
Title DOM-Based XSS in TR7's WAF-ASP
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 4.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-07-02T13:15:06.196Z

Reserved: 2026-03-24T13:29:09.973Z

Link: CVE-2026-4770

cve-icon Vulnrichment

Updated: 2026-07-02T13:15:02.754Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T11:30:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')