
CVE-2026-34810 Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/vpnfw.cgi. An authenticated attacker can inject … https://www.cve.org/CVERecord?id=CVE-2026-34810
Post summary
The post announces a stored cross‑site scripting flaw in Endian Firewall 3.3.25 or earlier, detailing the vulnerable parameter and the authentication requirement for exploitation.
