Junglewise Threat Intelligence

CVE-2026-34802: Endian Firewall stored XSS in salearn.cgi

CVE-2026-34802 · Severity: medium · CVSS 6.4 · Published 2026-04-02

Technologies: Endian Firewall Community. Vendors: Endian.

Executive brief

Endian Firewall, a security appliance used to protect corporate and community networks, contains a vulnerability in its administrative interface. An authorized user can upload malicious scripts that are saved on the device and then automatically run in the browsers of other administrators. This could allow a malicious insider to hijack administrative sessions or perform unauthorized actions on the firewall.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Endian Firewall version 3.3.25 and earlier. The flaw is located in the /cgi-bin/salearn.cgi component, which fails to properly neutralize user-supplied input in the 'remark', 'user', 'ham', and 'spam' parameters. An authenticated attacker with low privileges can submit a crafted request containing malicious JavaScript. This script is stored on the server and executed in the context of any user (typically an administrator) who later views the affected page. This can lead to session hijacking, unauthorized configuration changes, or further exploitation of the administrative interface.

Affected products

  • Endian Firewall Community up to and including 3.3.25

Timeline

  • 2026-04-02: disclosed
  • 2026-04-02: advisory

References

Related threats