Junglewise Threat Intelligence

CVE-2026-34807: Endian Firewall stored XSS in incoming.cgi remark parameter

CVE-2026-34807 · Severity: medium · CVSS 6.4 · Published 2026-04-02

Technologies: Endian Firewall Community. Vendors: Endian.

Executive brief

Endian Firewall, a security appliance used to protect network perimeters, contains a vulnerability that allows malicious code to be saved on its management interface. An attacker with basic login credentials can inject scripts that will run in the browsers of other administrators when they view specific configuration pages. This could lead to the theft of session cookies or unauthorized configuration changes by hijacking an administrator's session.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Endian Firewall version 3.3.25 and earlier. The flaw is located in the '/cgi-bin/incoming.cgi' component, which fails to properly neutralize user-supplied input in the 'remark' parameter. An authenticated attacker with low privileges can submit a malicious script that is permanently stored on the server. When an administrative user subsequently accesses the affected page, the script executes within their browser context. This can be leveraged to perform actions on behalf of the administrator or exfiltrate sensitive session information.

Affected products

  • Endian Firewall Community <= 3.3.25

Timeline

  • 2026-04-02: disclosed: Initial disclosure by VulnCheck
  • 2026-04-02: advisory: NVD published the CVE entry

References

Related threats