Executive brief
Endian Firewall, a security appliance used to protect corporate networks, is vulnerable to a security flaw in its certificate management interface. An authorized user can upload malicious code that will run in the browsers of other administrators when they view the certificate list. This could allow an attacker to hijack administrative sessions or perform unauthorized actions within the firewall management console.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in Endian Firewall versions up to and including 3.3.25. The vulnerability is located in the '/manage/ca/certificate/' endpoint and is triggered via the 'new_cert_name' parameter. An authenticated attacker with low privileges can inject malicious JavaScript into the certificate name field. This script is then stored on the server and executed in the context of any user (typically an administrator) who subsequently views the certificate management page. This can lead to session hijacking or unauthorized configuration changes.
Affected products
- Endian Firewall 3.3.25 and prior
Timeline
- 2026-04-02: disclosed
- 2026-04-02: advisory