Executive brief
Endian Firewall, a security appliance used to protect networks, contains a vulnerability that allows an authorized user to inject malicious scripts into the management interface. When other administrators view the affected configuration page, these scripts can execute automatically in their browser. This could lead to unauthorized actions being performed on behalf of other administrators or the theft of sensitive session information.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in Endian Firewall (Community edition) versions up to and including 3.3.25. The flaw is located in the /cgi-bin/vpnfw.cgi component, which fails to properly neutralize user-supplied input in the 'remark' parameter. An authenticated attacker with network access to the management interface can submit a malicious payload that is permanently stored on the server. When an unsuspecting user or administrator subsequently accesses the VPN firewall configuration page, the injected JavaScript executes within the context of their session. This can be used to bypass same-origin policy protections or perform administrative actions.
Affected products
- Endian Firewall Community up to and including 3.3.25
Timeline
- 2026-04-02: disclosed
- 2026-04-02: advisory