Executive brief
Endian Firewall, a security appliance used to protect corporate and community networks, contains a vulnerability that allows an authorized user to inject malicious scripts into the management interface. When other administrators view the affected configuration page, these scripts can execute automatically in their browser. This could lead to unauthorized actions being performed on behalf of other administrators or the theft of sensitive session information.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in Endian Firewall version 3.3.25 and earlier. The flaw is located in the /cgi-bin/uplinkeditor.cgi component, which fails to properly neutralize user-provided input in the 'NAME' parameter. An authenticated attacker with network access to the management interface can submit a malicious payload that is permanently stored on the server. When an unsuspecting user or administrator subsequently accesses the uplink editor page, the injected JavaScript executes within the context of their session. This can be used to bypass same-origin policy protections or perform administrative actions.
Affected products
- Endian Firewall Community <= 3.3.25
Timeline
- 2026-04-02: disclosed
- 2026-04-02: advisory