Executive brief
Endian Firewall, a security appliance used to protect corporate networks, is vulnerable to a security flaw in its email scanning management interface. An authorized user can inject malicious scripts into the system's domain routing settings. These scripts are then executed in the browsers of other administrators who view the page, potentially leading to unauthorized actions or the theft of sensitive session information.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in Endian Firewall version 3.3.25 and earlier. The vulnerability is located in the '/manage/smtpscan/domainrouting/' endpoint and is triggered by insufficient sanitization of the 'domain' parameter. An authenticated attacker with network access to the management interface can submit a malicious payload that is permanently stored on the server. When an administrative user subsequently navigates to the domain routing configuration page, the malicious JavaScript executes within the context of their session. This can be used to perform unauthorized administrative actions or exfiltrate session cookies.
Affected products
- Endian Firewall 3.3.25 and prior
Timeline
- 2026-04-02: disclosed: Initial disclosure by VulnCheck
- 2026-04-02: advisory: NVD publication date