PT-2026-29752 · Endian Technologies · Endian Firewall

Alex Williams

+1

·

Published

2026-04-02

·

Updated

2026-04-05

·

CVE-2026-34792

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Endian Firewall versions 3.3.25 and prior
Description Endian Firewall versions 3.3.25 and earlier permit authenticated users to execute arbitrary operating system commands through the DATE parameter of the '/cgi-bin/logs clamav.cgi' endpoint. The DATE parameter's value is used in constructing a file path passed to a Perl open() function, enabling command injection due to insufficient regular expression validation.
Recommendations Update Endian Firewall to a version later than 3.3.25.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-34792

Affected Products

Endian Firewall