
CVE-2026-34817 Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the ADDRESS BCC parameter to /cgi-bin/smtprouting.cgi. An authenticated attacker … https://www.cve.org/CVERecord?id=CVE-2026-34817
Post summary
The cited CVE describes a stored cross‑site scripting flaw in Endian Firewall (v3.3.25 and earlier) targeting the ADDRESS BCC parameter in smtprouting.cgi; no PoC, exploit code, active exploitation, or patch information is disclosed.
