Executive brief
Endian Firewall, a security appliance used to protect corporate networks, is vulnerable to a security flaw in its user management interface. An authorized user can inject malicious scripts into the system that will automatically run when other administrators view specific management pages. This could allow an attacker to hijack administrative sessions or perform unauthorized actions within the firewall management console.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in Endian Firewall versions up to and including 3.3.25. The vulnerability is located in the /cgi-bin/proxyuser.cgi component and is triggered via the 'user' parameter. An authenticated attacker with low privileges can submit a specially crafted string containing malicious JavaScript. This script is then stored on the server and executed in the context of any user (including administrators) who subsequently visits the affected page. This can lead to session hijacking, unauthorized configuration changes, or further escalation of privileges within the firewall's web interface.
Affected products
- Endian Firewall 3.3.25 and prior
Timeline
- 2026-04-02: disclosed
- 2026-04-02: advisory