Executive brief
Endian Firewall, a security appliance used to protect networks, contains a flaw that allows an authorized user to take full control of the system. By sending a specially crafted request to the log management interface, an attacker can execute unauthorized commands. This could lead to a complete compromise of the firewall, allowing attackers to intercept network traffic or disable security protections.
Technical details
An OS command injection vulnerability exists in Endian Firewall version 3.3.25 and prior within the /cgi-bin/logs_firewall.cgi component. The vulnerability is rooted in the improper validation of the 'DATE' parameter, which is used to construct a file path passed directly to a Perl open() call. Due to incomplete regular expression validation, an authenticated attacker can inject shell metacharacters to execute arbitrary commands with the privileges of the web server. This is a network-reachable exploit requiring low-level authentication (PR:L).
Affected products
- Endian Firewall Community up to and including 3.3.25
Timeline
- 2026-04-02: disclosed
- 2026-04-02: advisory