
CVE-2026-34801 Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/dhcp/fixed_leases/. An authenticated attacker can… https://www.cve.org/CVERecord?id=CVE-2026-34801
Post summary
A stored XSS vulnerability (CVE‑2026‑34801) is disclosed in Endian Firewall 3.3.25 and earlier, affecting the remark parameter in DHCP fixed leases, with no patches or exploits referenced.
