Executive brief
Endian Firewall, a security appliance used to protect network perimeters, is vulnerable to a security flaw in its management interface. An authorized user with low-level access can inject malicious scripts into the system's proxy policy settings. These scripts are then executed in the browsers of other administrators who view the affected configuration page, potentially allowing the attacker to hijack administrative sessions or perform unauthorized actions.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in Endian Firewall version 3.3.25 and earlier. The flaw is located in the '/cgi-bin/proxypolicy.cgi' component, which fails to properly neutralize user-supplied input in the 'mimetypes' parameter. An authenticated attacker with network access to the management interface can submit a crafted request containing malicious JavaScript. This script is permanently stored on the server and executes in the security context of any user (typically an administrator) who subsequently navigates to the proxy policy configuration page. This can lead to session hijacking, unauthorized configuration changes, or further escalation of privileges within the management console.
Affected products
- Endian Firewall Community <= 3.3.25
Timeline
- 2026-04-02: disclosed
- 2026-04-02: advisory