Junglewise Threat Intelligence

CVE-2026-34814: Endian Firewall stored XSS in proxygroup.cgi

CVE-2026-34814 · Severity: medium · CVSS 6.4 · Published 2026-04-02

Technologies: Endian Firewall Community. Vendors: Endian.

Executive brief

Endian Firewall, a security appliance used to protect corporate networks, is vulnerable to a security flaw in its management interface. An authorized user can inject malicious scripts into the system's configuration pages. When other administrators view these pages, the scripts could allow the attacker to perform unauthorized actions or steal sensitive session information.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Endian Firewall versions up to and including 3.3.25. The flaw is located in the /cgi-bin/proxygroup.cgi component, which fails to properly neutralize user-supplied input in the 'group' parameter. An authenticated attacker with network access to the management interface can submit a specially crafted request containing malicious JavaScript. This script is stored on the server and subsequently executed in the browser of any user (typically an administrator) who visits the affected configuration page, potentially leading to session hijacking or unauthorized configuration changes.

Affected products

  • Endian Firewall 3.3.25 and prior

Timeline

  • 2026-04-02: disclosed
  • 2026-04-02: advisory

References

Related threats