Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the destination parameter. Attackers can send POST requests to the routing endpoint with script payloads in the destination parameter to execute arbitrary JavaScript in users' browsers.
References
| Link | Resource |
|---|---|
| https://cdome.comodo.com/firewall/ | Product |
| https://secure.comodo.com/home/purchase.php?pid=106&license=try&track=9278&af=9278 | Not Applicable |
| https://www.exploit-db.com/exploits/46408 | Exploit |
| https://www.vulncheck.com/advisories/comodo-dome-firewall-reflected-cross-site-scripting-via-routing | Third Party Advisory VDB Entry |
Configurations
History
20 Feb 2026, 15:34
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:comodo:dome_firewall:*:*:*:*:*:*:*:* | |
| First Time |
Comodo
Comodo dome Firewall |
|
| References | () https://cdome.comodo.com/firewall/ - Product | |
| References | () https://secure.comodo.com/home/purchase.php?pid=106&license=try&track=9278&af=9278 - Not Applicable | |
| References | () https://www.exploit-db.com/exploits/46408 - Exploit | |
| References | () https://www.vulncheck.com/advisories/comodo-dome-firewall-reflected-cross-site-scripting-via-routing - Third Party Advisory, VDB Entry |
19 Feb 2026, 13:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-19 13:16
Updated : 2026-02-20 15:34
NVD link : CVE-2019-25409
Mitre link : CVE-2019-25409
CVE.ORG link : CVE-2019-25409
JSON object : View
Products Affected
comodo
- dome_firewall
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
