CVE-2025-2418
Deferred
Deferred - Pending Action
Open Redirect in TR7 Cyber Defense WAF Enables Phishing
Publication date: 2026-02-16
Last updated on: 2026-05-07
Assigner: Computer Emergency Response Team of the Republic of Turkey
Description
Description
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in TR7 Cyber ββDefense Inc. Web Application Firewall allows Phishing.
This issue affects Web Application Firewall: from 4.30 before v1.4.0.117.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| tr7_cyber_defense_inc | web_application_firewall | From 4.30 (inc) to 16022026 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-601 | The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect. |