
CVE-2026-34821 Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/vpnauthentication/user/. An authenticated attacke… https://www.cve.org/CVERecord?id=CVE-2026-34821
Post summary
The entry confirms a stored XSS vulnerability in Endian Firewall, giving technical details but lacking any demonstrated exploitation or patch information.
