
CVE-2026-34823 Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /manage/password/web/. An authenticated attacker can inje… https://www.cve.org/CVERecord?id=CVE-2026-34823
Post summary
The text announces a stored XSS vulnerability in Endian Firewall versions 3.3.25 and earlier, detailing the affected parameter, but offers no PoC, exploit code, or remediation information.
