Executive brief
Endian Firewall, a security appliance used to protect corporate networks and manage VPN access, is vulnerable to a security flaw in its user management interface. An attacker with existing access to the system can inject malicious scripts into user profile fields. When an administrator or another user views the affected management page, these scripts could execute, potentially allowing the attacker to hijack sessions or perform unauthorized actions within the firewall management console.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in Endian Firewall versions up to and including 3.3.25. The vulnerability is located in the '/manage/vpnauthentication/user/' endpoint and is triggered by insufficient sanitization of the 'remark' parameter. An authenticated attacker with network access to the management interface can submit a malicious payload that is permanently stored on the server. When a different user (such as an administrator) navigates to the user management page, the payload executes in the context of their browser session. This can lead to session hijacking, unauthorized configuration changes, or further escalation within the management interface.
Affected products
- Endian Endian Firewall <= 3.3.25
Timeline
- 2026-04-02: disclosed
- 2026-04-02: advisory