
CVE-2026-34804 Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the dscp parameter to /manage/qos/rules/. An authenticated attacker can inject ar… https://www.cve.org/CVERecord?id=CVE-2026-34804
Post summary
A stored XSS vulnerability (CVE‑2026‑34804) exists in Endian Firewall v3.3.25 and earlier, triggered through the dscp parameter; the text notes authenticated attackers can inject payloads but offers no proof‑of‑concept, exploit tool, or patch details.
