Junglewise Threat Intelligence

CVE-2026-34804: Endian Firewall stored XSS in QoS rules dscp parameter

CVE-2026-34804 · Severity: medium · CVSS 6.4 · Published 2026-04-02

Technologies: Endian Firewall Community. Vendors: Endian.

Executive brief

Endian Firewall, a security appliance used to protect network perimeters, is vulnerable to a security flaw in its Quality of Service (QoS) management interface. An authorized user can inject malicious scripts into the system's configuration rules. When other administrators view these rules, the scripts execute automatically, potentially allowing the attacker to hijack administrative sessions or perform unauthorized actions on the firewall.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Endian Firewall version 3.3.25 and earlier. The vulnerability is located in the '/manage/qos/rules/' endpoint and is triggered by improper neutralization of the 'dscp' parameter. An authenticated attacker with network access to the management interface can submit a crafted request containing malicious JavaScript. This script is stored on the server and executed in the context of any user (typically an administrator) who subsequently navigates to the affected Quality of Service rules page. This can lead to session hijacking, unauthorized configuration changes, or further exploitation of the administrative interface.

Affected products

  • Endian Firewall Community <= 3.3.25

Timeline

  • 2026-04-02: disclosed
  • 2026-04-02: advisory

References

Related threats