
CVE-2026-34820 Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/ipsec/. An authenticated attacker can inject arbi… https://www.cve.org/CVERecord?id=CVE-2026-34820
Post summary
The tweet announces a stored XSS flaw (CVE-2026-34820) in Endian Firewall 3.3.25 and earlier, affecting the remark parameter in /manage/ipsec with authenticated users, but provides no PoC, exploit, patch or active exploitation details.
