Executive brief
Endian Firewall, a security appliance used to protect network traffic, is vulnerable to a security flaw in its administrative interface. An authorized user can inject malicious code into the system's host management settings. This code is then saved and automatically runs when other administrators view the page, potentially allowing an attacker to hijack sessions or perform unauthorized actions on the firewall.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in Endian Firewall version 3.3.25 and earlier. The vulnerability is located in the '/manage/dnsmasq/hosts/' endpoint and is triggered by insufficient sanitization of the 'remark' parameter. An authenticated attacker with network access to the management interface can submit a malicious payload that is permanently stored on the server. When another user (such as an administrator) accesses the hosts management page, the malicious JavaScript executes in the context of their browser session. This can lead to session hijacking, unauthorized configuration changes, or further escalation within the management console.
Affected products
- Endian Firewall Community <= 3.3.25
Timeline
- 2026-04-02: disclosed
- 2026-04-02: advisory