Executive brief
Endian Firewall, a security appliance used to protect corporate and community networks, contains a vulnerability in its administrative interface. An authorized user with low-level access can inject malicious scripts into the system's configuration pages. These scripts are then executed when other administrators view the affected settings, potentially leading to unauthorized actions or the theft of sensitive session information.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in Endian Firewall version 3.3.25 and earlier. The flaw is located in the /cgi-bin/smtpdomains.cgi component, which fails to properly neutralize user-supplied input provided via the DOMAIN parameter. An authenticated attacker with network access can submit a malicious payload that is permanently stored on the server. When an unsuspecting user (such as another administrator) accesses the SMTP domains configuration page, the malicious JavaScript executes in the context of their browser session. This can be used to hijack sessions, modify configurations, or perform actions on behalf of the victim user.
Affected products
- Endian Firewall Community up to and including 3.3.25
Timeline
- 2026-04-02: disclosed
- 2026-04-02: advisory