Executive brief
Endian Firewall, a security appliance used to protect corporate and community networks, contains a vulnerability that allows an attacker to inject malicious scripts into the management interface. An attacker with basic user credentials can save a malicious script that will automatically run when an administrator or another user views the affected settings page. This could lead to the theft of session cookies, unauthorized administrative actions, or the redirection of users to malicious websites.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in Endian Firewall version 3.3.25 and earlier. The flaw is located in the /cgi-bin/xtaccess.cgi component, which fails to properly sanitize input provided in the 'remark' parameter. An authenticated attacker with low privileges can submit a crafted request containing malicious JavaScript. This script is stored on the server and subsequently executed in the browser context of any user (including administrators) who navigates to the page where the remark is displayed. This can be leveraged to perform session hijacking or unauthorized configuration changes.
Affected products
- Endian Firewall Community up to and including 3.3.25
Timeline
- 2026-04-02: disclosed
- 2026-04-02: advisory