
CVE-2026-34798 Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/routing.cgi. An authenticated attacker can injec… https://www.cve.org/CVERecord?id=CVE-2026-34798
Post summary
The statement announces a stored XSS vulnerability (CVE‑2026‑34798) affecting Endian Firewall 3.3.25 and earlier, detailing the attack vector but not providing any PoC, exploit code, patch, or evidence of active exploitation.
