Junglewise Threat Intelligence

CVE-2026-34818: Endian Firewall stored XSS in dnsmasq local domains remark parameter

CVE-2026-34818 · Severity: medium · CVSS 6.4 · Published 2026-04-02

Technologies: Endian Firewall Community. Vendors: Endian.

Executive brief

Endian Firewall, a security appliance used to protect network perimeters, is vulnerable to a security flaw where malicious scripts can be saved within the system's configuration pages. An attacker with basic login credentials can inject these scripts into the 'remark' field of the local domains management section. When an administrator later views that page, the script executes in their browser, potentially allowing the attacker to perform unauthorized actions or steal sensitive session information.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Endian Firewall versions up to and including 3.3.25. The vulnerability is located in the '/manage/dnsmasq/localdomains/' endpoint, specifically within the 'remark' parameter, which fails to properly neutralize user-supplied input. An authenticated attacker with low privileges can submit a malicious payload that is permanently stored on the server. When a victim (typically an administrator) accesses the local domains management page, the payload executes in the context of their session. This can lead to session hijacking, unauthorized configuration changes, or further escalation of privileges within the web management interface.

Affected products

  • Endian Firewall Community <= 3.3.25

Timeline

  • 2026-04-02: disclosed
  • 2026-04-02: advisory

References

Related threats