Executive brief
Endian Firewall, a security appliance used to protect corporate networks, is vulnerable to a security flaw in its management interface. An authorized user can inject malicious code into the system's routing configuration notes. If another administrator views these notes, the code could execute in their browser, potentially allowing the attacker to perform unauthorized actions or steal sensitive session information.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in Endian Firewall versions up to and including 3.3.25. The vulnerability is located in the '/cgi-bin/routing.cgi' component and is triggered by insufficient sanitization of the 'remark' parameter. An authenticated attacker with network access to the management interface can submit a malicious payload that is permanently stored on the server. When an administrative user subsequently accesses the routing configuration page, the injected JavaScript executes within the context of their session, potentially leading to session hijacking or unauthorized configuration changes.
Affected products
- Endian Endian Firewall <= 3.3.25
Timeline
- 2026-04-02: disclosed
- 2026-04-02: advisory