Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-41230

28
FAUCET Score

OVERVIEW Froxlor, an open source server administration platform, contains a DNS record injection vulnerability in versions prior to 2.3.6. The DomainZones::add() function fails to validate DNS record types and does not sanitize newline characters in the content field. When uncommon DNS record types such as NAPTR, PTR, or HINFO are submitted, input validation is completely bypassed, allowing embedded newlines to persist through database storage and into BIND zone files. SEVERITY The vulnerability carries a CVSS score of 8.5 (High) with a network attack vector requiring low complexity and low privileges. An authenticated customer can exploit this remotely without user interaction. The primary impact is integrity compromise through injection of arbitrary DNS records and BIND directives including $INCLUDE, $ORIGIN, and $GENERATE, enabling potential DNS hijacking or lateral movement. A secondary availability impact is possible through malformed directives. EXPLOITATION STATUS There is no evidence of active exploitation in the wild. The vulnerability does not appear on the CISA Known Exploited Vulnerabilities catalog and is listed as inactive on the Hot List. Community attention and exploit code availability are minimal, though the technical simplicity of the attack warrants attention from organizations operating Froxlor instances. Immediate patching to version 2.3.6 or later is recommended.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.3.6CPE matchmatch criteria
cpe:2.3:a:froxlor:froxlor:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.5HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
LOW
Exploitability Score
3.1
Impact Score
4.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.35%
Probability of exploitation in next 30 days
EPSS Percentile
27.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0035 is in the 15th percentile among its peer group of 17,844 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

composerpatch availablevia ghsa
Product: froxlor/froxlorFixed in: 2.3.6
github_advisorypatch availablevia nvd_reference
View patch

Vendor Advisories (1)

composerGHSA-47hf-23pw-3m8chigh

Froxlor has a BIND Zone File Injection via Unsanitized DNS Record Content in DomainZones::add()

Apr 16, 2026

References

github.com / froxlor/froxlor/commit/47a8af5d9523cb6ec94567405cfc2e294d3a1442
Patch
github.com / froxlor/froxlor/releases/tag/2.3.6
Release Notes
github.com / froxlor/froxlor/security/advisories/GHSA-47hf-23pw-3m8c
ExploitMitigationVendor Advisory