CVE-2026-34790
HIGH
NVD
CVSS Score
7.1
Severity
HIGH
Published
Apr 02, 2026
Vendor
unknown
Description
Endian Firewall version 3.3.25 and prior allow authenticated users to delete arbitrary files via directory traversal in the remove ARCHIVE parameter to /cgi-bin/backup.cgi. The remove ARCHIVE parameter value is used to construct a file path without sanitization of directory traversal sequences, which is then passed to an unlink() call.