Executive brief
A security vulnerability exists in the TR7 Cyber Defense Web Application Firewall, a system designed to protect websites from cyberattacks. An attacker could exploit this flaw to execute malicious scripts in the browser of a logged-in user. This could lead to unauthorized actions being performed on behalf of the user or the theft of sensitive session information.
Technical details
A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the TR7 Cyber Defense Web Application Firewall (WAF-ASP). The flaw stems from the improper neutralization of user-supplied input during web page generation, allowing malicious scripts to be executed within the Document Object Model (DOM) environment. An attacker with low-privileged network access can exploit this by tricking a victim into interacting with a specially crafted link or page. Successful exploitation allows for the execution of arbitrary JavaScript in the context of the victim's session. The issue affects versions v1.0.42.239 through v1.4.0.117 and has been addressed in version v1.4.0.117.
Affected products
- TR7 Cyber Defense Inc. Web Application Firewall (WAF-ASP) v1.0.42.239 to v1.4.0.117
Timeline
- 2026-07-02: advisory
- 2026-07-02: disclosed