Executive brief
Endian Firewall, a security appliance used to protect corporate and community networks, contains a vulnerability in its Quality of Service (QoS) management interface. An authorized user with low-level access can inject malicious scripts into the system's configuration. These scripts are then executed in the browsers of other administrators when they view the affected management page, potentially leading to unauthorized actions or the theft of sensitive session information.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in Endian Firewall version 3.3.25 and earlier. The flaw is located in the '/manage/qos/classes/' endpoint, where the 'name' parameter fails to properly neutralize user-supplied input before it is stored and subsequently rendered in the web interface. An authenticated attacker with network access to the management console can submit a malicious payload that will execute arbitrary JavaScript in the context of any user (such as an administrator) who later navigates to the QoS classes page. This can lead to session hijacking or unauthorized configuration changes. The vulnerability is tracked as CWE-79.
Affected products
- Endian Firewall Community up to and including 3.3.25
Timeline
- 2026-04-02: disclosed
- 2026-04-02: advisory