CVE-2026-34797Disclosure(endian / firewall_community)

LOWCVSS 8.7 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch endian firewall_community systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_smtp.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open() call, which allows command injection due to an incomplete regular expression validation.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • firewall_community

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-04-02); latest day: 2
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
firewall_community

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-04-02: 2Mentions · 2026-04-03: 1Mentions · 2026-04-07: 2Patch / Workaround · 2026-04-07: 1Technical Details · 2026-04-02: 2Technical Details · 2026-04-03: 104-0204-0304-07
Signal classification3 categories
Disclosure
240.0%
General
240.0%
Patch
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-022
Disclosure1General1
2026-04-031
Disclosure1
2026-04-072
General1Patch1
Full discourse5 posts
  • Firmis Labs@FirmisLabs
    Patch

    ask your AI: "check if my infrastructure uses Endian Firewall version 3.3.25 or earlier" then: "update Endian Firewall to the latest version that patches CVE-2026-34797 and verify log forwarding still works"

    Post summary

    The text advises updating Endian Firewall to the latest patch for CVE-2026-34797 and verifying log forwarding.

    1000034
    1 followersView on X
  • Firmis Labs@FirmisLabs
    General

    CVE-2026-34797 · NIST 8.8/10 https://nvd.nist.gov/vuln/detail/CVE-2026-34797

    Post summary

    The text merely notes the existence of CVE-2026-34797 and its NIST CVSS score, with no further technical or actionable information.

    1000031
    1 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-34797 - High Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_smtp.cgi. The DATE parameter value is used to const... https://www.thehackerwire.com/vulnerability/CVE-2026-34797/ https://t.co/k01k34J5Dr

    Post summary

    The tweet announces a high‑severity CVE in Endian Firewall that permits authenticated users to run arbitrary OS commands via the DATE parameter. It shares basic technical details but lacks any PoC, exploit code, or patch information.

    0000057
    163 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-34797 Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_smtp.cgi. The DATE paramet… https://www.cve.org/CVERecord?id=CVE-2026-34797

    Post summary

    A vulnerability in Endian Firewall 3.3.25 and earlier allows authenticated users to execute arbitrary operating‑system commands through the DATE parameter of /cgi-bin/logs_smtp.cgi.

    0000091
    56.9K followersView on X
  • CVEFind.com@CveFindCom
    General

    [CVE-2026-34797: HIGH] Alert: Endian Firewall v3.3.25 and earlier versions are vulnerable to OS command injection via DATE parameter in /cgi-bin/logs_smtp.cgi. Attackers can execute arbitrary commands. Updat...#cve,CVE-2026-34797,#cybersecurity https://cvefind.com/CVE-2026-34797

    Post summary

    The post announces a high‑severity OS command injection flaw in Endian Firewall (v3.3.25 and earlier) but gives no proof of concept, exploit tools, active exploitation evidence, or patch details.

    0000043
    617 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appendianfirewall_community---

Explore more