Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Smoothwall

First CVE: May 5, 2003Active for: 23 yearsTotal CVEs: 28
22.6
VTI Score
Low

Smoothwall develops a suite of network security and content-filtering appliances—including Smoothwall Express, NetworkGuardian, SchoolGuardian, and SmoothGuardian—that are deployed for gateway filtering and access control in schools and enterprise environments. Its vulnerability profile, while modest in overall volume, centers on a narrow but strategically positioned product line and recurs through web-facing input-handling flaws, particularly cross-site scripting and cross-site request forgery vulnerabilities in the management and filtering interfaces. Public exploit code has an elevated tendency to be available for vulnerabilities affecting this vendor, reflecting the appeal of these appliances as targets for gaining administrative access or bypassing content controls. The exposure pattern is characteristic of embedded security appliances where management interfaces and filtering logic are frequent sources of access-control and input-validation weaknesses. Current severity, exploitation activity, and detailed exposure counts are shown alongside this summary.

FAUCET AI Generated
28
Total CVEs
More Total CVEs than 97% of tracked vendors
1.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
6.2
Avg CVSS Score
Higher Avg CVSS Score than 35% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Smoothwall over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 5, 2003
23 years ago
Most Recent CVE
Mar 30, 2026
116 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (28 CVEs).

28 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2003-0209HIGH
Integer overflow in the TCP stream reassembly module (stream4) for Snort 2.0 and earlier allows remote attackers to execute arbitrary code via large sequence numbers in packets, wh
May 5, 200310.056NOYES
CVE-2011-5284MEDIUM
Cross-site request forgery (CSRF) vulnerability in the web management interface in httpd/cgi-bin/shutdown.cgi in Smoothwall Express 3.1 and 3.0 SP3 and earlier allows remote attack
Dec 31, 20146.832NOYES
CVE-2011-1085HIGH
CSRF vulnerability in Smoothwall Express 3.
Feb 7, 20208.828NONO
CVE-2011-5283MEDIUM
Cross-site scripting (XSS) vulnerability in the web management interface in httpd/cgi-bin/ipinfo.cgi in Smoothwall Express 3.1 and 3.0 SP3 and earlier allows remote attackers to in
Dec 31, 20144.326NOYES
CVE-2019-25395MEDIUM
Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple stored cross-site scripting vulnerabilities in the preferences.cgi script that allow attackers to inject malicious
Feb 16, 20266.123NONO
CVE-2019-25379HIGH
Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains stored and reflected cross-site scripting vulnerabilities in the urlfilter.cgi endpoint that allow attackers to inject mali
Feb 16, 20267.223NONO
CVE-2026-27508MEDIUM
Smoothwall Express versions prior to 3.1 Update 13 contain a reflected cross-site scripting vulnerability in the /redirect.cgi endpoint due to improper sanitation of the url parame
Mar 30, 20266.122NONO
CVE-2019-25381MEDIUM
Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple reflected cross-site scripting vulnerabilities in the hosts.cgi script that allow attackers to inject malicious sc
Feb 16, 20266.122NONO
CVE-2026-26352MEDIUM
Smoothwall Express versions prior to 3.1 Update 13 contain a stored cross-site scripting vulnerability in the /cgi-bin/vpnmain.cgi script due to improper sanitation of the VPN_IP p
Mar 30, 20265.421NONO
CVE-2019-25394MEDIUM
Smoothwall Express 3.1-SP4-polar-x86_64-update9 contains multiple stored cross-site scripting vulnerabilities in the modem.cgi script that allow attackers to inject malicious scrip
Feb 16, 20266.121NONO
View all 28 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products28 CVEs
89%
11%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network21 (75.0%)
Unknown7 (25.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low21 (75.0%)
High0 (0.0%)
Unknown7 (25.0%)
User Interaction
None1 (3.6%)
Unknown7 (25.0%)
Required20 (71.4%)
Privileges Required
Low1 (3.6%)
High0 (0.0%)
None20 (71.4%)
Unknown7 (25.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (28 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
10.7% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Smoothwall.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Smoothwall — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Smoothwall's Products

View all 3 CNAs →

Top CWEs