Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-34797

HIGH NVD
CVSS Score 8.8
Severity HIGH
Published Apr 02, 2026
Vendor unknown

Description

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_smtp.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open() call, which allows command injection due to an incomplete regular expression validation.

References