Two high-severity vulnerabilities, CVE-2026-34794 and CVE-2026-34791, were disclosed in Endian Firewall 3.3.25 and earlier, exposing authenticated users to arbitrary operating system command execution through the DATE parameter in the /cgi-bin/logs_ids.cgi and /cgi-bin/logs_proxy.cgi endpoints. Both flaws were classified as CWE-78 command injection issues and stem from incomplete regular-expression validation that lets attacker-controlled input influence a file path passed to a Perl open() call.
The vulnerabilities carry the same CVSS v3.1 score vector, AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, indicating network-reachable exploitation with low attack complexity and low privileges, with high impact on confidentiality, integrity, and availability. The disclosures were submitted through VulnCheck and reference vendor support resources from Endian, highlighting that organizations running affected firewall versions should review exposure of these CGI components and prioritize remediation.

Map this exposure pattern across your cloud, code, and identities.
4 events from the most recent confirmed update back to the earliest known activity.
A fourth authenticated command injection vulnerability, CVE-2026-34797, was disclosed in Endian Firewall 3.3.25 and earlier. The flaw affects the DATE parameter in /cgi-bin/logs_smtp.cgi, where incomplete validation allows arbitrary OS command execution through a Perl open() call.
A third authenticated command injection vulnerability, CVE-2026-34796, was disclosed in Endian Firewall 3.3.25 and earlier. The flaw affects the DATE parameter in /cgi-bin/logs_openvpn.cgi, where incomplete validation allows arbitrary OS command execution through a Perl open() call.
A fifth authenticated command injection vulnerability, CVE-2026-34795, was disclosed in Endian Firewall 3.3.25 and earlier. The flaw affects the DATE parameter in /cgi-bin/logs_log.cgi, where incomplete validation allows arbitrary OS command execution through a Perl open() call.
Two authenticated command injection vulnerabilities affecting Endian Firewall 3.3.25 and earlier were disclosed. The flaws involve insufficient validation of the DATE parameter in /cgi-bin/logs_proxy.cgi and /cgi-bin/logs_ids.cgi, allowing arbitrary OS command execution via a Perl open() call.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
6 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.