Executive brief
Endian Firewall, a security appliance used to protect and manage network traffic, contains a vulnerability that allows an attacker to inject malicious scripts into the management interface. An authorized user could save a specially crafted comment that, when viewed by another administrator, executes hidden code in their browser. This could lead to unauthorized actions being performed on behalf of other administrators or the theft of sensitive session information.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in Endian Firewall version 3.3.25 and earlier. The flaw is located in the '/cgi-bin/zonefw.cgi' component, specifically within the 'remark' parameter, which fails to properly neutralize user-supplied input before it is stored and rendered in the web interface. An authenticated attacker with network access to the management console can submit a malicious script that will execute in the context of any user who subsequently views the firewall zone configuration page. This can result in session hijacking or unauthorized configuration changes. Users are advised to check for updates in the Endian Community release notes.
Affected products
- Endian Firewall Community up to and including 3.3.25
Timeline
- 2026-04-02: disclosed
- 2026-04-02: advisory