Junglewise Threat Intelligence

CVE-2026-34808: Endian Firewall stored XSS in outgoingfw.cgi remark parameter

CVE-2026-34808 · Severity: medium · CVSS 6.4 · Published 2026-04-02

Technologies: Endian Firewall Community. Vendors: Endian.

Executive brief

Endian Firewall, a security appliance used to protect network perimeters, is vulnerable to a security flaw in its management interface. An authorized user with low-level access can inject malicious scripts into the firewall's configuration settings. These scripts will run in the browser of any other administrator who views the affected settings page, potentially allowing the attacker to hijack administrative sessions or perform unauthorized actions.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Endian Firewall version 3.3.25 and earlier. The vulnerability is located in the '/cgi-bin/outgoingfw.cgi' component and is triggered by insufficient sanitization of the 'remark' parameter. An authenticated attacker with network access to the management interface can submit a malicious payload that is permanently stored on the server. When an unsuspecting administrator subsequently accesses the firewall's outgoing rules page, the malicious JavaScript executes within the context of their session. This can lead to session hijacking, unauthorized configuration changes, or further exploitation of the administrative interface.

Affected products

  • Endian Firewall Community 3.3.25 and prior

Timeline

  • 2026-04-02: disclosed
  • 2026-04-02: advisory

References

Related threats