
CVE-2026-34808 Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/outgoingfw.cgi. An authenticated attacker can in… https://www.cve.org/CVERecord?id=CVE-2026-34808
Post summary
The entry discloses a stored XSS flaw in Endian Firewall 3.3.25 and prior that is triggered through the remark parameter in outgoingfw.cgi.
