📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global insider Education HIGH 5h Global supply_chain Software Development and Technology HIGH 10h Global apt Government/Critical Infrastructure CRITICAL 11h Global vulnerability Enterprise Software / Data Analytics CRITICAL 12h Global vulnerability Artificial Intelligence and Technology HIGH 16h Global general Technology and Artificial Intelligence MEDIUM 19h Global general Technology and Artificial Intelligence HIGH 20h Global vulnerability Higher Education CRITICAL 1d Global data_breach Government HIGH 1d Global supply_chain Software Development and Open Source Communities CRITICAL 1d Global insider Education HIGH 5h Global supply_chain Software Development and Technology HIGH 10h Global apt Government/Critical Infrastructure CRITICAL 11h Global vulnerability Enterprise Software / Data Analytics CRITICAL 12h Global vulnerability Artificial Intelligence and Technology HIGH 16h Global general Technology and Artificial Intelligence MEDIUM 19h Global general Technology and Artificial Intelligence HIGH 20h Global vulnerability Higher Education CRITICAL 1d Global data_breach Government HIGH 1d Global supply_chain Software Development and Open Source Communities CRITICAL 1d Global insider Education HIGH 5h Global supply_chain Software Development and Technology HIGH 10h Global apt Government/Critical Infrastructure CRITICAL 11h Global vulnerability Enterprise Software / Data Analytics CRITICAL 12h Global vulnerability Artificial Intelligence and Technology HIGH 16h Global general Technology and Artificial Intelligence MEDIUM 19h Global general Technology and Artificial Intelligence HIGH 20h Global vulnerability Higher Education CRITICAL 1d Global data_breach Government HIGH 1d Global supply_chain Software Development and Open Source Communities CRITICAL 1d
Vulnerabilities

CVE-2026-30932

High ⚡ Exploit Available
Froxlor is open source server administration software. Prior to version 2.3.5, the DomainZones.add API endpoint (accessible to customers with DNS enabled) does not validate the content field for sever
CWE-74 — Weakness Type
Published: Mar 24, 2026  ·  Modified: Mar 30, 2026  ·  Source: NVD
CVSS v3
8.8
🔗 NVD Official
📄 Description (English)

Froxlor is open source server administration software. Prior to version 2.3.5, the DomainZones.add API endpoint (accessible to customers with DNS enabled) does not validate the content field for several DNS record types (LOC, RP, SSHFP, TLSA). An attacker can inject newlines and BIND zone file directives (e.g. $INCLUDE) into the zone file that gets written to disk when the DNS rebuild cron job runs. This issue has been patched in version 2.3.5.

🤖 AI Executive Summary

Froxlor versions prior to 2.3.5 contain a critical DNS zone file injection vulnerability in the DomainZones.add API endpoint. Attackers with DNS-enabled customer accounts can inject BIND directives (such as $INCLUDE) into DNS records, leading to arbitrary file inclusion and potential remote code execution when the DNS rebuild cron job executes. This vulnerability is actively exploitable and requires immediate patching.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: Apr 23, 2026 01:06
🇸🇦 Saudi Arabia Impact Assessment
This vulnerability poses significant risk to Saudi hosting providers, domain registrars, and organizations using Froxlor for DNS management. Primary impact sectors include: (1) Telecommunications providers (STC, Mobily, Zain) managing DNS infrastructure; (2) Government entities (NCA, CITC) operating DNS services; (3) Banking sector (SAMA-regulated institutions) relying on Froxlor for domain management; (4) Energy sector (ARAMCO subsidiaries) using Froxlor for infrastructure DNS. The vulnerability enables privilege escalation from customer-level access to server-level code execution, potentially compromising entire hosting infrastructure and downstream customers' domains.
🏢 Affected Saudi Sectors
Telecommunications (STC, Mobily, Zain) Government (NCA, CITC) Banking (SAMA-regulated institutions) Energy (ARAMCO, subsidiaries) Hosting Providers Domain Registrars Healthcare (MOH DNS infrastructure)
⚖️ Saudi Risk Score (AI)
8.9
/ 10.0
🔧 Remediation Steps (English)
IMMEDIATE ACTIONS:
1. Identify all Froxlor installations in your environment and verify versions prior to 2.3.5
2. Restrict API access to DomainZones.add endpoint to trusted administrators only
3. Disable DNS functionality for non-essential customer accounts until patching is complete
4. Review DNS zone files for suspicious $INCLUDE directives or unusual content

PATCHING:
1. Upgrade Froxlor to version 2.3.5 or later immediately
2. Test patches in staging environment before production deployment
3. Verify DNS zone file integrity post-upgrade

COMPENSATING CONTROLS (if immediate patching not possible):
1. Implement input validation at firewall/WAF level to block requests containing BIND directives ($INCLUDE, $DEFINE, etc.)
2. Monitor DNS zone file modifications in real-time using file integrity monitoring (FIM)
3. Restrict cron job execution permissions to read-only zone file access
4. Implement API rate limiting and authentication hardening for DomainZones endpoints

DETECTION:
1. Search zone files for patterns: \$INCLUDE, \$DEFINE, \$ORIGIN with suspicious paths
2. Monitor API logs for DomainZones.add requests containing newline characters (%0A, %0D)
3. Alert on unexpected DNS zone file modifications outside scheduled rebuild windows
4. Monitor for LOC, RP, SSHFP, TLSA record creation with embedded directives
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. حدد جميع تثبيتات Froxlor في بيئتك والتحقق من الإصدارات السابقة للإصدار 2.3.5
2. قيد الوصول إلى API لنقطة نهاية DomainZones.add للمسؤولين الموثوقين فقط
3. عطل وظيفة DNS لحسابات العملاء غير الضرورية حتى اكتمال التصحيح
4. راجع ملفات منطقة DNS بحثًا عن توجيهات $INCLUDE المريبة أو المحتوى غير المعتاد

التصحيح:
1. قم بترقية Froxlor إلى الإصدار 2.3.5 أو أحدث على الفور
2. اختبر التصحيحات في بيئة التجميع قبل نشر الإنتاج
3. تحقق من سلامة ملف منطقة DNS بعد الترقية

الضوابط البديلة (إذا لم يكن التصحيح الفوري ممكنًا):
1. تنفيذ التحقق من الإدخال على مستوى جدار الحماية/WAF لحظر الطلبات التي تحتوي على توجيهات BIND
2. مراقبة تعديلات ملف منطقة DNS في الوقت الفعلي باستخدام مراقبة سلامة الملفات
3. تقييد أذونات تنفيذ مهام cron للوصول إلى ملفات المنطقة بقراءة فقط
4. تنفيذ تحديد معدل API وتقوية المصادقة لنقاط نهاية DomainZones

الكشف:
1. ابحث في ملفات المنطقة عن الأنماط: $INCLUDE و $DEFINE و $ORIGIN مع المسارات المريبة
2. مراقبة سجلات API لطلبات DomainZones.add التي تحتوي على أحرف سطر جديد
3. تنبيه على تعديلات ملف منطقة DNS غير المتوقعة خارج نوافذ إعادة البناء المجدولة
4. مراقبة إنشاء سجلات LOC و RP و SSHFP و TLSA مع توجيهات مضمنة
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
ECC 2024 A.14.2.1 - Information security change management ECC 2024 A.12.6.1 - Management of technical vulnerabilities ECC 2024 A.14.3.1 - Segregation of development, test and production environments
🔵 SAMA CSF
SAMA CSF ID.BE-3.1 - Organizational resilience objectives SAMA CSF PR.DS-6 - Data is protected from unauthorized access SAMA CSF DE.CM-1 - The network is monitored to detect potential cybersecurity events
🟡 ISO 27001:2022
ISO 27001:2022 A.12.6.1 - Management of technical vulnerabilities ISO 27001:2022 A.14.2.1 - Change management ISO 27001:2022 A.8.3.1 - User registration and access rights management ISO 27001:2022 A.14.3.1 - Segregation of development, test and production environments
🟣 PCI DSS v4.0.1
PCI DSS 6.2 - Ensure all system components and software are protected from known vulnerabilities PCI DSS 6.5.1 - Injection flaws prevention
📦 Affected Products / CPE 1 entries
froxlor:froxlor
📊 CVSS Score
8.8
/ 10.0 — High
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredL — Low / Local
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityH — High
IntegrityH — High
AvailabilityH — High
📋 Quick Facts
Severity High
CVSS Score8.8
CWECWE-74
Exploit ✓ Yes
Patch ✓ Yes
Published 2026-03-24
Source Feed nvd
Views 4
🇸🇦 Saudi Risk Score
8.9
/ 10.0 — Saudi Risk
Priority: CRITICAL
🏷️ Tags
exploit-available patch-available CWE-74
Share this CVE

💬 Comments

0
Loading comments
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.