Endian Firewall Stored From XSS to...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### Vulnerability Summary The following advisory describes a stored cross site scripting that can be used to trigger remote code execution in Endian Firewall version 5.0.3. Endian Firewall is a “turnkey Linux security distribution, which is an independent, unified security management operating system. The Endian Firewall is based on a hardened Linux operating system.” ### Credit An independent security researcher has reported this vulnerability to Beyond Security’s SecuriTeam Secure Disclosure program. ### Vendor response Endian has released patches to address this vulnerability. For more information: https://help.endian.com/hc/en-us/articles/115012996087 ### Vulnerability details Endian Firewall is a firewall/gateway based on Linux. Its concept of trusted, untrusted and DMZ network is based on color that it uses to tag different network segments: * GREEN – Trusted network * RED – Untrusted network * ORANGE – DMZ * BLUE – WiFi User controlled input is not sufficiently sanitized, by...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息