PT-2026-29760 · Endian · Endian Firewall

Alex Williams

+1

·

Published

2026-04-02

·

Updated

2026-04-02

·

CVE-2026-34800

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Endian Firewall versions 3.3.25 and prior
Description Endian Firewall versions 3.3.25 and earlier are susceptible to stored cross-site scripting (XSS). The issue is located in the /cgi-bin/uplinkeditor.cgi endpoint, specifically through manipulation of the NAME parameter. An authenticated attacker can inject arbitrary JavaScript code that is then stored and executed when other users access the affected page.
Recommendations Update Endian Firewall to a version later than 3.3.25.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-34800

Affected Products

Endian Firewall