
CVE-2026-34818 Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/dnsmasq/localdomains/. An authenticated attacker … https://www.cve.org/CVERecord?id=CVE-2026-34818
Post summary
A stored XSS flaw in Endian Firewall (v3.3.25 and earlier) via the remark parameter has been disclosed, but no PoC, exploitation tools, or patches are mentioned.
