
CVE-2026-34814 Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the group parameter to /cgi-bin/proxygroup.cgi. An authenticated attacker can inj… https://www.cve.org/CVERecord?id=CVE-2026-34814
Post summary
The text announces a stored XSS vulnerability in Endian Firewall 3.3.25 and earlier, detailing the affected parameter and endpoint, but does not mention exploitation, fixes, or a PoC.
