Impact
The flaw is a DOM‑Based Cross‑Site Scripting vulnerability in TR7 Cyber Defense Inc.'s Web Application Firewall (WAF‑ASP). The firewall does not neutralize user input when it builds client‑side content, allowing an attacker to inject malicious JavaScript that is executed within the victim’s browser. The classification as CWE‑79 suggests the issue stems from insufficient input sanitization. There is no evidence of additional impact beyond the execution of injected script.
Affected Systems
The vulnerability exists in all releases of TR7 Cyber Defense Inc.'s WAF‑ASP from firmware version 1.0.42.239 up to, but not including, version 1.4.0.117. Any user running a firmware revision within this range is affected.
Risk and Exploitability
With a CVSS score of 4.6 the weakness is rated low‑to‑moderate severity, and an EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The flaw is not yet listed in the CISA KEV catalog. The likely attack vector involves a malicious web page or crafted input that passes through the firewall and reaches the victim’s browser; no publicly available exploit is known, so exploitation likelihood is inferred from the provided metrics.
OpenCVE Enrichment