Junglewise Threat Intelligence

CVE-2026-34805: Endian Firewall stored XSS in dnat.cgi remark parameter

CVE-2026-34805 · Severity: medium · CVSS 6.4 · Published 2026-04-02

Technologies: Endian Firewall Community. Vendors: Endian.

Executive brief

Endian Firewall, a security appliance used to protect corporate networks, contains a vulnerability that allows an authenticated user to inject malicious scripts into the management interface. When an administrator or another user views the affected configuration page, these scripts can execute automatically in their browser. This could lead to unauthorized actions being performed on behalf of the administrator or the theft of sensitive session information.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Endian Firewall versions up to and including 3.3.25. The flaw is located in the '/cgi-bin/dnat.cgi' component, specifically within the 'remark' parameter, which fails to properly neutralize user-supplied input before it is stored and rendered in the web interface. An attacker with low-privileged authenticated access can submit a malicious payload that will execute arbitrary JavaScript in the context of any user who subsequently views the DNAT configuration page. This can result in session hijacking or unauthorized configuration changes. The vulnerability is tracked as CVE-2026-34805.

Affected products

  • Endian Firewall 3.3.25 and prior

Timeline

  • 2026-04-02: disclosed
  • 2026-04-02: advisory

References

Related threats