Junglewise Threat Intelligence

CVE-2026-34806: Endian Firewall stored XSS in snat.cgi remark parameter

CVE-2026-34806 · Severity: medium · CVSS 6.4 · Published 2026-04-02

Technologies: Endian Firewall Community. Vendors: Endian.

Executive brief

Endian Firewall, a security appliance used to protect networks, contains a vulnerability that allows an authenticated user to inject malicious scripts into the management interface. These scripts are saved on the device and will run automatically when other administrators view the affected configuration page. This could lead to unauthorized actions being performed on behalf of other administrators or the theft of sensitive session information.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Endian Firewall version 3.3.25 and earlier. The flaw is located in the '/cgi-bin/snat.cgi' component, specifically due to improper neutralization of the 'remark' parameter. An authenticated attacker with network access to the management interface can submit a crafted request containing malicious JavaScript. This script is stored on the server and executes in the context of any user (such as a high-privileged administrator) who subsequently views the SNAT configuration page. This can result in session hijacking or unauthorized configuration changes.

Affected products

  • Endian Firewall Community <= 3.3.25

Timeline

  • 2026-04-02: disclosed
  • 2026-04-02: advisory

References

Related threats