Junglewise Threat Intelligence

CVE-2026-34823: Endian Firewall stored XSS in remark parameter

CVE-2026-34823 · Severity: medium · CVSS 6.4 · Published 2026-04-02

Technologies: Endian Firewall Community. Vendors: Endian.

Executive brief

Endian Firewall, a security appliance used to protect corporate and community networks, contains a vulnerability that allows an authenticated user to inject malicious scripts into the management interface. If an administrator or another user views the affected settings page, the script could execute in their browser, potentially leading to unauthorized actions or the theft of session information. This could compromise the integrity of the firewall management console.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Endian Firewall (Community edition) versions up to and including 3.3.25. The flaw is located in the '/manage/password/web/' endpoint, where the 'remark' parameter fails to properly neutralize user-supplied input. An authenticated attacker with low privileges can submit a malicious payload that is permanently stored on the server. When an administrative user subsequently accesses the affected page, the payload executes within the context of their session. This can be used to perform unauthorized configuration changes or hijack administrative sessions.

Affected products

  • Endian Firewall Community up to and including 3.3.25

Timeline

  • 2026-04-02: disclosed: Initial disclosure by VulnCheck
  • 2026-04-02: advisory: NVD publication date

References

Related threats