Junglewise Threat Intelligence

CVE-2026-34793: Endian Firewall OS command injection in logs_firewall.cgi

CVE-2026-34793 · Severity: high · CVSS 8.8 · Published 2026-04-02

Technologies: Endian Firewall Community. Vendors: Endian.

Executive brief

Endian Firewall, a security appliance used to protect networks, contains a flaw that allows an authorized user to take full control of the system. By sending a specially crafted request to the log management interface, an attacker can execute unauthorized commands. This could lead to a complete compromise of the firewall, allowing attackers to intercept network traffic or disable security protections.

Technical details

An OS command injection vulnerability exists in Endian Firewall version 3.3.25 and prior within the /cgi-bin/logs_firewall.cgi component. The vulnerability is rooted in the improper validation of the 'DATE' parameter, which is used to construct a file path passed directly to a Perl open() call. Due to incomplete regular expression validation, an authenticated attacker can inject shell metacharacters to execute arbitrary commands with the privileges of the web server. This is a network-reachable exploit requiring low-level authentication (PR:L).

Affected products

  • Endian Firewall Community up to and including 3.3.25

Timeline

  • 2026-04-02: disclosed
  • 2026-04-02: advisory

References

Related threats