5.1

CVSS4.0

CVE-2026-34810 - Endian Firewall /cgi-bin/vpnfw.cgi remark Stored Cross-Site Scripting

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/vpnfw.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page.

๐Ÿ“… Published: April 2, 2026, 2:46 p.m. ๐Ÿ”„ Last Modified: April 2, 2026, 8:20 p.m.

5.1

CVSS4.0

CVE-2026-34809 - Endian Firewall /cgi-bin/zonefw.cgi remark Stored Cross-Site Scripting

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/zonefw.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page.

๐Ÿ“… Published: April 2, 2026, 2:46 p.m. ๐Ÿ”„ Last Modified: April 2, 2026, 8:20 p.m.

5.1

CVSS4.0

CVE-2026-34808 - Endian Firewall /cgi-bin/outgoingfw.cgi remark Stored Cross-Site Scripting

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/outgoingfw.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page.

๐Ÿ“… Published: April 2, 2026, 2:46 p.m. ๐Ÿ”„ Last Modified: April 2, 2026, 8:20 p.m.

5.1

CVSS4.0

CVE-2026-34807 - Endian Firewall /cgi-bin/incoming.cgi remark Stored Cross-Site Scripting

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/incoming.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page.

๐Ÿ“… Published: April 2, 2026, 2:46 p.m. ๐Ÿ”„ Last Modified: April 2, 2026, 8:20 p.m.

5.1

CVSS4.0

CVE-2026-34806 - Endian Firewall /cgi-bin/snat.cgi remark Stored Cross-Site Scripting

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/snat.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page.

๐Ÿ“… Published: April 2, 2026, 2:46 p.m. ๐Ÿ”„ Last Modified: April 2, 2026, 8:20 p.m.

5.1

CVSS4.0

CVE-2026-34805 - Endian Firewall /cgi-bin/dnat.cgi remark Stored Cross-Site Scripting

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/dnat.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page.

๐Ÿ“… Published: April 2, 2026, 2:45 p.m. ๐Ÿ”„ Last Modified: April 2, 2026, 8:20 p.m.

5.1

CVSS4.0

CVE-2026-34804 - Endian Firewall /manage/qos/rules/ dscp Stored Cross-Site Scripting

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the dscp parameter to /manage/qos/rules/. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page.

๐Ÿ“… Published: April 2, 2026, 2:45 p.m. ๐Ÿ”„ Last Modified: April 2, 2026, 8:20 p.m.

5.1

CVSS4.0

CVE-2026-34803 - Endian Firewall /manage/qos/classes/ name Stored Cross-Site Scripting

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the name parameter to /manage/qos/classes/. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page.

๐Ÿ“… Published: April 2, 2026, 2:45 p.m. ๐Ÿ”„ Last Modified: April 2, 2026, 8:20 p.m.

5.1

CVSS4.0

CVE-2026-34802 - Endian Firewall /cgi-bin/salearn.cgi remark user ham spam Stored Cross-Site Scripting

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark user ham spam parameter to /cgi-bin/salearn.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page.

๐Ÿ“… Published: April 2, 2026, 2:45 p.m. ๐Ÿ”„ Last Modified: April 2, 2026, 8:20 p.m.

5.1

CVSS4.0

CVE-2026-34801 - Endian Firewall /manage/dhcp/fixed_leases/ remark Stored Cross-Site Scripting

Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/dhcp/fixed_leases/. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page.

๐Ÿ“… Published: April 2, 2026, 2:45 p.m. ๐Ÿ”„ Last Modified: April 2, 2026, 8:20 p.m.
Total resulsts: 341929
Page 12 of 34,193
ยซ previous page ยป next page
Filters