Junglewise Threat Intelligence

CVE-2026-34801: Endian Firewall stored XSS in DHCP fixed leases remark parameter

CVE-2026-34801 · Severity: medium · CVSS 6.4 · Published 2026-04-02

Technologies: Endian Firewall Community. Vendors: Endian.

Executive brief

Endian Firewall, a security appliance used to protect and manage network traffic, is vulnerable to a security flaw in its DHCP management interface. An authorized user can inject malicious scripts into the system's configuration notes, which will then execute in the browsers of other administrators who view that page. This could lead to unauthorized actions being performed on behalf of other administrators or the theft of sensitive session information.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Endian Firewall version 3.3.25 and earlier. The vulnerability is located in the '/manage/dhcp/fixed_leases/' endpoint and is triggered by insufficient sanitization of the 'remark' parameter. An authenticated attacker with low privileges can submit a crafted string containing malicious JavaScript. This script is stored on the server and executed in the context of any user (typically an administrator) who subsequently navigates to the fixed leases management page. This can be used to hijack administrative sessions or perform unauthorized configuration changes.

Affected products

  • Endian Firewall Community up to and including 3.3.25

Timeline

  • 2026-04-02: disclosed
  • 2026-04-02: advisory

References

Related threats