Junglewise Threat Intelligence

CVE-2026-34794: Endian Firewall OS command injection in logs_ids.cgi

CVE-2026-34794 · Severity: high · CVSS 8.8 · Published 2026-04-02

Technologies: Endian Firewall Community. Vendors: Endian.

Executive brief

Endian Firewall, a security appliance used to protect corporate and community networks, contains a vulnerability that allows logged-in users to take full control of the system. By sending a specially crafted request to the log management interface, an attacker can execute unauthorized commands. This could lead to a complete compromise of the firewall, allowing attackers to intercept network traffic or disable security protections.

Technical details

An OS command injection vulnerability (CWE-78) exists in Endian Firewall version 3.3.25 and earlier. The issue resides in the '/cgi-bin/logs_ids.cgi' script, where the 'DATE' parameter is used to construct a file path passed directly to a Perl 'open()' call. Due to incomplete regular expression validation, an authenticated attacker can inject shell metacharacters into the parameter. Successful exploitation allows for arbitrary command execution with the privileges of the web server user, potentially leading to full system compromise. The attack requires network access and valid user credentials.

Affected products

  • Endian Firewall Community up to and including 3.3.25

Timeline

  • 2026-04-02: disclosed
  • 2026-04-02: advisory

References

Related threats