Junglewise Threat Intelligence

CVE-2026-4772: TR7 Cyber Defense WAF-ASP stored XSS

CVE-2026-4772 · Severity: medium · CVSS 5.4 · Published 2026-07-02

Executive brief

A security vulnerability exists in the TR7 Cyber Defense WAF-ASP, a web application firewall designed to protect websites from cyberattacks. An attacker with low-level access can inject malicious scripts that are permanently stored on the system. When an administrator or another user views the affected page, these scripts could execute, potentially leading to unauthorized actions or the theft of sensitive session information.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in TR7 Cyber Defense Inc. WAF-ASP versions v1.0.324.900 through v1.4.0.117. The flaw stems from the improper neutralization of user-supplied input during web page generation (CWE-79). A remote attacker with low privileges can submit malicious scripts that are stored on the server and subsequently executed in the context of other users' browsers, such as administrators. The vulnerability has a CVSS score of 5.4, requiring user interaction to trigger the payload. Users are advised to upgrade to version v1.4.0.117 or later to remediate the issue.

Affected products

  • TR7 Cyber Defense Inc. WAF-ASP v1.0.324.900 to v1.4.0.117

Timeline

  • 2026-07-02: advisory
  • 2026-07-02: disclosed

References

Related threats