
CVE-2026-34792 · NIST 8.8/10 https://nvd.nist.gov/vuln/detail/CVE-2026-34792
Post summary
Only the CVE ID and its NIST CVSS score are provided; no PoC, exploit, patch, or activity details are included.
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_clamav.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open() call, which allows command injection due to an incomplete regular expression validation.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
STABLE
If you run products in this scope, you should treat this CVE as relevant to your environment.
| Date | Total | Labels |
|---|
| 2026-04-02 | 2 | Disclosure2 |
| 2026-04-05 | 1 | Disclosure1 |
| 2026-04-07 | 1 | General1 |

CVE-2026-34792 · NIST 8.8/10 https://nvd.nist.gov/vuln/detail/CVE-2026-34792
Post summary
Only the CVE ID and its NIST CVSS score are provided; no PoC, exploit, patch, or activity details are included.

🟠 CVE-2026-34792 - High Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_clamav.cgi. The DATE parameter value is used to con... https://www.thehackerwire.com/vulnerability/CVE-2026-34792/ https://t.co/w0M72Cn5tH
Post summary
The post reveals a new CVE (CVE‑2026‑34792) where authenticated users of Endian Firewall 3.3.25 or earlier can run arbitrary OS commands via a DATE parameter in /cgi-bin/logs_clamav.cgi.

CVE-2026-34792 Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_clamav.cgi. The DATE param… https://www.cve.org/CVERecord?id=CVE-2026-34792
Post summary
The text announces CVE-2026-34792, detailing an authenticated remote command execution flaw in Endian Firewall 3.3.25 and earlier, without providing PoC, exploit code, or patch information.

[CVE-2026-34792: HIGH] Vulnerability in Endian Firewall v3.3.25 & earlier allows authenticated users to run OS commands via /cgi-bin/logs_clamav.cgi DATE parameter, exploiting incomplete validation.#cve,CVE-2026-34792,#cybersecurity https://cvefind.com/CVE-2026-34792
Post summary
This post discloses a high‑severity vulnerability in Endian Firewall (CVE‑2026‑34792) that permits authenticated users to execute OS commands through a CGI parameter, but it does not include any PoC, exploit code, mention of active exploitation, or a patch.
1 of 1 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | endian | firewall_community | - | - | - |