
CVE-2026-34799 Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/dnsmasq/hosts/. An authenticated attacker can inj… https://www.cve.org/CVERecord?id=CVE-2026-34799
Post summary
CVE-2026-34799 is a stored XSS vulnerability in Endian Firewall 3.3.25 and earlier, exploitable via the remark parameter in the dnsmasq hosts management interface. No PoC, exploit code, or patch information is provided in the brief notice.
