Executive brief
Endian Firewall, a security appliance used to protect corporate and community networks, contains a flaw that allows logged-in users to take full control of the system. By sending a specially crafted request to the log viewing component, an attacker can run unauthorized commands. This could lead to a total compromise of the firewall, allowing attackers to intercept network traffic or disable security protections.
Technical details
An OS command injection vulnerability (CWE-78) exists in Endian Firewall version 3.3.25 and earlier within the /cgi-bin/logs_log.cgi component. The vulnerability is rooted in the improper validation of the 'DATE' parameter, which is used to construct a file path passed directly to a Perl open() call. Due to incomplete regular expression validation, an authenticated attacker can inject shell metacharacters into the parameter to execute arbitrary commands with the privileges of the web server. The attack is reachable over the network but requires valid user credentials.
Affected products
- Endian Firewall Community up to and including 3.3.25
Timeline
- 2026-04-02: disclosed
- 2026-04-02: advisory