📦 Dome Firewall

by Comodo

🔍 What is Dome Firewall?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2019-25419

HIGH CVSS 7.2 Feb 19, 2026

Comodo Dome Firewall 2.7.0 contains a stored cross-site scripting vulnerability in the schedule endpoint. Attackers can inject malicious JavaScript via the SCHNAME parameter in POST requests, which ex...

CVE-2019-25422

HIGH CVSS 7.2 Feb 19, 2026

CVE-2019-25422 is a cross-site scripting vulnerability in Comodo Dome Firewall that allows attackers to inject malicious JavaScript through the vpnfw endpoint. Attackers can execute arbitrary scripts ...

CVE-2019-25405

HIGH CVSS 7.2 Feb 19, 2026

Comodo Dome Firewall 2.7.0 contains a stored cross-site scripting vulnerability in the license activation endpoint. Attackers can inject malicious JavaScript via the newLicense parameter, which execut...

CVE-2019-25430

MEDIUM CVSS 6.1 Feb 19, 2026

Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability in the vpn_users endpoint. Unauthenticated attackers can inject malicious JavaScript via crafted username parameters ...

CVE-2019-25424

MEDIUM CVSS 6.1 Feb 19, 2026

Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability in the EXCEPTIONSITELIST parameter. Attackers can inject malicious JavaScript via POST requests to the https_exceptio...

CVE-2019-25426

MEDIUM CVSS 6.1 Feb 19, 2026

Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability in its dnsmasq endpoint. Attackers can inject malicious JavaScript via crafted POST requests to the TRANSPARENT_SOURC...

CVE-2019-25428

MEDIUM CVSS 6.1 Feb 19, 2026

This vulnerability allows attackers to inject malicious JavaScript into Comodo Dome Firewall's web interface through crafted POST requests. When users access the vulnerable openvpn_users endpoint, the...

CVE-2019-25421

MEDIUM CVSS 6.1 Feb 19, 2026

CVE-2019-25421 is a cross-site scripting vulnerability in Comodo Dome Firewall that allows attackers to inject malicious JavaScript through the policyfw endpoint. This enables execution of arbitrary c...

CVE-2019-25415

MEDIUM CVSS 6.1 Feb 19, 2026

Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability in the hotspot_permanent_users endpoint. Attackers can inject malicious JavaScript via the MACADDRESSES parameter in ...

CVE-2019-25417

MEDIUM CVSS 6.1 Feb 19, 2026

Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability in the QoS rules management endpoint. Attackers can inject malicious JavaScript via the protocol parameter in POST re...

CVE-2019-25409

MEDIUM CVSS 6.1 Feb 19, 2026

Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability in the destination parameter of routing endpoints. Attackers can inject malicious JavaScript via POST requests, which...

CVE-2019-25411

MEDIUM CVSS 6.1 Feb 19, 2026

Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability in the DHCP configuration endpoint. Attackers can inject malicious JavaScript via the GATEWAY_GREEN parameter in POST...

CVE-2019-25413

MEDIUM CVSS 6.1 Feb 19, 2026

Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability in the ID parameter of the /manage/ips/rules/ endpoint. Unauthenticated attackers can inject malicious JavaScript tha...

CVE-2019-25404

MEDIUM CVSS 6.4 Feb 19, 2026

Comodo Dome Firewall 2.7.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts into admin management parameters. When administrators ac...

CVE-2019-25407

MEDIUM CVSS 6.1 Feb 19, 2026

Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability in the backup schedule interface. Attackers can inject malicious JavaScript via crafted POST requests to the backupsc...

CVE-2019-25402

MEDIUM CVSS 6.1 Feb 19, 2026

Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability in the login page's username parameter. Unauthenticated attackers can inject malicious JavaScript that executes in vi...