Junglewise Threat Intelligence

CVE-2026-34820: Endian Firewall stored XSS in IPsec remark parameter

CVE-2026-34820 · Severity: medium · CVSS 6.4 · Published 2026-04-02

Technologies: Endian Firewall Community. Vendors: Endian.

Executive brief

Endian Firewall, a security appliance used to protect corporate networks, contains a vulnerability in its IPsec management interface. An authorized user can inject malicious code into the system's configuration notes. This code then runs in the browsers of other administrators who view the page, potentially allowing an attacker to hijack sessions or perform unauthorized administrative actions.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Endian Firewall version 3.3.25 and earlier. The flaw is located in the 'remark' parameter within the /manage/ipsec/ endpoint, which fails to properly neutralize user-supplied input before it is stored and rendered. An authenticated attacker with network access to the management interface can submit a malicious payload that will execute arbitrary JavaScript in the context of any user who subsequently views the IPsec management page. This can lead to session hijacking or unauthorized configuration changes. The vulnerability is tracked as CVE-2026-34820.

Affected products

  • Endian Endian Firewall <= 3.3.25

Timeline

  • 2026-04-02: disclosed
  • 2026-04-02: advisory

References

Related threats