Executive brief
Endian Firewall, a security appliance used to protect corporate and community networks, contains a vulnerability that allows logged-in users to take full control of the system. By sending a specially crafted request to the OpenVPN logging interface, an attacker can execute unauthorized commands. This could lead to a complete compromise of the firewall, allowing attackers to intercept network traffic or disable security protections.
Technical details
An OS command injection vulnerability exists in Endian Firewall version 3.3.25 and earlier within the /cgi-bin/logs_openvpn.cgi component. The vulnerability is rooted in the improper validation of the 'DATE' parameter, which is used to construct a file path passed directly to a Perl open() call. Due to an incomplete regular expression check, an authenticated attacker can inject shell metacharacters to execute arbitrary commands with the privileges of the web server. This is reachable over the network by any user with valid credentials for the management interface.
Affected products
- Endian Firewall Community <= 3.3.25
Timeline
- 2026-04-02: disclosed
- 2026-04-02: advisory