Froxlor vulnerabilities
3 CVEs tracked
Froxlor server administration software appears in our reports with critical authentication and access control vulnerabilities. Key themes include the bypass of two-factor authentication (TOTP) enforcement in API paths (CVE-2026-52793) and the circumvention of centralized request validation allowing unauthorized state-changing commands (CVE-2026-55593). Additionally, insufficient sanitization of user-supplied data in the "DomainZones.add" API command (CVE-2026-54543) leaves DNS configurations open to manipulation. Defenders should immediately upgrade Froxlor instances to version 2.3.8, review API key management, and monitor for anomalous activity, particularly regarding DNS record functionality.
Azərbaycanca: Froxlor server idarəetmə proqramı hesabatlarımızda kritik autentifikasiya və giriş nəzarəti zəiflikləri ilə bağlı xatırlanır. Əsas mövzular arasında API autentifikasiyasında iki faktorlu doğrulamanın (TOTP) yoxlanılmaması (CVE-2026-52793) və mərkəzləşdirilmiş sorğu yoxlamasından yan keçmə (CVE-2026-55593) vasitəsilə icazəsiz əmrlərin icrası riski var. Bundan əlavə, "DomainZones.add" API komandasında istifadəçi tərəfindən təqdim edilən məlumatların sanitarlaşdırılmaması (CVE-2026-54543) DNS konfiqurasiyasını manipulyasiyaya açıq qoyur. Müdafiəçilər Froxlor instansiyalarını dərhal 2.3.8 versiyasına yeniləməli, API açarı idarəetməsini yoxlamalı və xüsusilə DNS qeyd funksionallığı üzərində anormal aktivliyə nəzarət etməlidir.
This vendor's CVEs3
This hub is built from skopnix's own reporting on Froxlor: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.