Junglewise Threat Intelligence

CVE-2026-34817: Endian Firewall stored XSS in smtprouting.cgi

CVE-2026-34817 · Severity: medium · CVSS 6.4 · Published 2026-04-02

Technologies: Endian Firewall Community. Vendors: Endian.

Executive brief

Endian Firewall, a security appliance used to protect corporate and community networks, contains a vulnerability that allows an attacker to inject malicious scripts into the management interface. An attacker with low-level access can use this to target administrators, potentially leading to the theft of session information or unauthorized actions within the firewall's control panel. This could compromise the integrity of the network security settings.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Endian Firewall version 3.3.25 and earlier. The flaw is located in the /cgi-bin/smtprouting.cgi component, specifically within the handling of the 'ADDRESS BCC' parameter. An authenticated attacker with network access to the management interface can submit a crafted request containing malicious JavaScript. This script is then stored on the server and executed in the browser of any user (typically an administrator) who subsequently views the SMTP routing configuration page. This can lead to session hijacking or unauthorized configuration changes.

Affected products

  • Endian Firewall Community up to and including 3.3.25

Timeline

  • 2026-04-02: disclosed
  • 2026-04-02: advisory

References

Related threats