
CVE-2026-34802 Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark user ham spam parameter to /cgi-bin/salearn.cgi. An authenticated atta… https://www.cve.org/CVERecord?id=CVE-2026-34802
Post summary
The text discloses that Endian Firewall versions 3.3.25 and earlier are vulnerable to stored XSS through a specific parameter. No PoC, exploit, patch, or active exploitation details are provided.
