Junglewise Threat Intelligence

CVE-2026-34797: Endian Firewall OS command injection in logs_smtp.cgi

CVE-2026-34797 · Severity: high · CVSS 8.8 · Published 2026-04-02

Technologies: Endian Firewall Community. Vendors: Endian.

Executive brief

Endian Firewall, a security appliance used to protect corporate and community networks, contains a vulnerability that allows an authorized user to take full control of the system. By sending a specially crafted request to the log management interface, an attacker can bypass security controls to run unauthorized commands. This could lead to a complete compromise of the firewall, allowing attackers to intercept network traffic, access sensitive data, or disrupt business operations.

Technical details

An OS command injection vulnerability (CWE-78) exists in Endian Firewall version 3.3.25 and earlier within the /cgi-bin/logs_smtp.cgi script. The vulnerability is rooted in the improper validation of the 'DATE' parameter, which is used to construct a file path passed directly to a Perl open() call. Due to incomplete regular expression validation, an authenticated attacker can inject shell metacharacters into the parameter to execute arbitrary commands with the privileges of the web server. This attack is reachable over the network but requires valid user credentials.

Affected products

  • Endian Firewall <= 3.3.25

Timeline

  • 2026-04-02: disclosed
  • 2026-04-02: advisory

References

Related threats