Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Smoothwall — Vulnerabilities & Security Advisories 21

Browse all 21 CVE security advisories affecting Smoothwall. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Smoothwall operates as a provider of network security appliances, primarily delivering content filtering, web protection, and firewall services for enterprise and educational environments. Its software stack has historically been susceptible to a range of critical vulnerabilities, including remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws. These weaknesses often stem from insufficient input validation and improper access controls within its web management interface. Recent records indicate approximately 21 Common Vulnerabilities and Exposures (CVEs), reflecting ongoing challenges in patching legacy components. While the vendor maintains a security advisory process, the accumulation of these defects highlights persistent risks in its architecture. Organizations relying on these appliances must prioritize regular firmware updates and strict network segmentation to mitigate potential exploitation, ensuring that administrative interfaces remain isolated from untrusted networks to prevent unauthorized system compromise.

Top products by Smoothwall: Smoothwall Express Express
CVE IDTitleCVSSSeverityPublished
CVE-2026-27508 Smoothwall Express < 3.1 Update 13 Reflected XSS in redirect.cgi via url Parameter — ExpressCWE-79 5.4 Medium2026-03-30
CVE-2026-26352 Smoothwall Express < 3.1 Update 13 Stored XSS in vpnmain.cgi via VPN_IP Parameter — ExpressCWE-79 5.4 Medium2026-03-30
CVE-2019-25395 Smoothwall Express 3.1 'preferences.cgi' Cross-Site Scripting — Smoothwall ExpressCWE-79 7.2 High2026-02-16
CVE-2019-25394 Smoothwall Express 3.1 'modem.cgi' Cross-Site Scripting — Smoothwall ExpressCWE-79 7.2 High2026-02-16
CVE-2019-25393 Smoothwall Express 3.1 'smoothinfo.cgi' Cross-Site Scripting — Smoothwall ExpressCWE-79 6.1 Medium2026-02-16
CVE-2019-25392 Smoothwall Express 3.1 'iptools.cgi' Cross-Site Scripting — Smoothwall ExpressCWE-79 6.1 Medium2026-02-16
CVE-2019-25390 Smoothwall Express 3.1 'interfaces.cgi' Cross-Site Scripting — Smoothwall ExpressCWE-79 5.4 Medium2026-02-16
CVE-2019-25389 Smoothwall Express 3.1 'timedaccess.cgi' Cross-Site Scripting — Smoothwall ExpressCWE-79 6.1 Medium2026-02-16
CVE-2019-25388 Smoothwall Express 3.1 'ipblock.cgi' Cross-Site Scripting — Smoothwall ExpressCWE-79 6.1 Medium2026-02-16
CVE-2019-25387 Smoothwall Express 3.1 'xtaccess.cgi' Cross-Site Scripting — Smoothwall ExpressCWE-79 6.1 Medium2026-02-16
CVE-2019-25386 Smoothwall Express 3.1 'dmzholes.cgi' Cross-Site Scripting — Smoothwall ExpressCWE-79 6.1 Medium2026-02-16
CVE-2019-25385 Smoothwall Express 3.1 'outgoing.cgi' Cross-Site Scripting — Smoothwall ExpressCWE-79 6.1 Medium2026-02-16
CVE-2019-25384 Smoothwall Express 3.1 'portfw.cgi' Cross-Site Scripting — Smoothwall ExpressCWE-79 6.1 Medium2026-02-16
CVE-2019-25382 Smoothwall Express 3.1 'time.cgi' Cross-Site Scripting — Smoothwall ExpressCWE-79 6.1 Medium2026-02-16
CVE-2019-25383 Smoothwall Express 3.1 'apcupsd.cgi' Cross-Site Scripting — Smoothwall ExpressCWE-79 6.1 Medium2026-02-16
CVE-2019-25381 Smoothwall Express 3.1 'hosts.cgi' Cross-Site Scripting — Smoothwall ExpressCWE-79 6.1 Medium2026-02-16
CVE-2019-25380 Smoothwall Express 3.1 'dhcp.cgi' Cross-Site Scripting — Smoothwall ExpressCWE-79 6.1 Medium2026-02-16
CVE-2019-25379 Smoothwall Express 3.1 'urlfilter.cgi' Cross-Site Scripting — Smoothwall ExpressCWE-79 7.2 High2026-02-16
CVE-2019-25378 Smoothwall Express 3.1 'proxy.cgi' Cross-Site Scripting — Smoothwall ExpressCWE-79 6.1 Medium2026-02-16
CVE-2011-1085 Smoothwall Express 跨站请求伪造漏洞 — Smoothwall Express 8.8 -2020-02-07
CVE-2011-1084 Smoothwall Express 跨站脚本漏洞 — Smoothwall Express 6.1 -2020-02-07

This page lists every published CVE security advisory associated with Smoothwall. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.