Collax Security Gateway: stored cross-site scripting through LLDP neighbour data in the interface detail view
A device on the same layer 2 segment plants stored script through a crafted LLDP frame that runs in the admin origin when an administrator opens the interface detail view.
Advisory ID: TP-2026-064
Product: Collax Security Gateway (German UTM, firewall, mail and SSL-VPN appliance; also affects Collax Business Server and Groupware Suite)
Vulnerability type: Stored cross-site scripting (CWE-79)
CVE: pending (MITRE CNA-LR)
CVSS 3.1: 7.4 (High) · CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Vendor advisory: Collax release notes CSG 7.2.48
Affected versions: 7.2.46 and earlier
Fixed in: 7.2.48
Reported: 01 September 2026
Summary
Collax Security Gateway records LLDP neighbours on its network interfaces and shows each neighbour's name, description and inventory in the interface detail view of the admin interface. These strings come from LLDP frames that any device on the same layer 2 segment can send. The LLDP parser trims whitespace only and re-emits each TLV with no HTML encoding, and the accessors return the values raw. The detail form renders the neighbour fields as typeless
Root cause
AKLib/Network/Interface/LLDP/Parse.pm:42-51 trims the TLV text and calls $writer->dataElement($lastTag, $text), after which XML::Parser decodes entities back to literal < and >, so no HTML encoding occurs.
The chassis, MED inventory and port accessors return those values raw, and Interface.pm hands the neighbour list to the form.
The form renders the neighbour fields as typeless
In html/gui/qx/ak/index.js the Display widget escapes only boolean, bytesize, date and json; any other string, a typeless value included, reaches setLabel(e) raw, and the label control is created with rich=true, so the string is interpreted as HTML.
The rich label is an intentional qooxdoo feature; the defect is the attacker-set LLDP TLV reaching it through the typeless-defaults-to-rich fail-open.
Proof of Concept
Schematically: from a device on the same layer 2 segment.
LLDP frame, system-description TLV (or system-name / port-description / MED inventory):
<event-handler payload>
A plain
Impact
- Stored script in the :8001 admin origin, triggered when an administrator opens the interface detail view.
- No CSP, X-Content-Type-Options or X-Frame-Options header anywhere on the appliance, so the injected markup renders.
- The auth_cookie is base64(user:password) and not HttpOnly, so the script discloses the plaintext admin password.
- The source is a layer-2-adjacent device with no appliance credentials; the payload persists in the neighbour table until viewed.
References
Is Something Like This in Your Software?
Our team found this vulnerability during its work. Have your applications tested by the same specialists, with a penetration test from turingpoint.
