Executive brief
Endian Firewall, a security appliance used to protect networks, contains a vulnerability that allows an authorized user to inject malicious scripts into the management interface. When other administrators view the affected configuration page, these scripts can execute automatically in their browser. This could lead to unauthorized actions being performed on behalf of other administrators or the theft of sensitive session information.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in Endian Firewall version 3.3.25 and earlier. The flaw is located in the '/cgi-bin/openvpnclient.cgi' component, which fails to properly neutralize user-supplied input in the 'REMARK' parameter. An authenticated attacker with network access to the management interface can submit a crafted request containing malicious JavaScript. This script is then stored on the server and executed in the context of any user (typically an administrator) who subsequently visits the OpenVPN client configuration page. This can result in session hijacking or unauthorized configuration changes.
Affected products
- Endian Firewall Community <= 3.3.25
Timeline
- 2026-04-02: advisory: Initial advisory published by VulnCheck
- 2026-04-02: disclosed: CVE-2026-34819 published