PT-2026-29755 · Endian Technologies · Endian Firewall

Alex Williams

+1

·

Published

2026-04-02

·

Updated

2026-04-04

·

CVE-2026-34795

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Endian Firewall versions 3.3.25 and prior
Description Endian Firewall versions 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to the '/cgi-bin/logs log.cgi' API endpoint. The DATE parameter value is used to construct a file path that is passed to a Perl open() call, which allows command injection due to an incomplete regular expression validation.
Recommendations Update Endian Firewall to a version later than 3.3.25.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-34795

Affected Products

Endian Firewall