
CVE-2026-34800 Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the NAME parameter to /cgi-bin/uplinkeditor.cgi. An authenticated attacker can in… https://www.cve.org/CVERecord?id=CVE-2026-34800
Post summary
The text announces a stored XSS vulnerability (CVE‑2026‑34800) in Endian Firewall versions 3.3.25 and earlier, where authenticated attackers can inject scripts via the NAME parameter in /cgi-bin/uplinkeditor.cgi.
