CVE-2026-34797 is a critical command injection vulnerability affecting Endian Firewall versions 3.3.25 and prior, allowing authenticated users to execute arbitrary OS commands. This flaw stems from insufficient validation of the DATE parameter in /cgi-bin/logs_smtp.cgi, which is then used in a Perl open() call. With a CVSSv3.1 score of 8.8 High, it presents a network attack vector, low attack complexity, and requires only low privileges, enabling high impact on confidentiality, integrity, and availability. Despite its severity, there is currently no evidence of active exploitation (KEV) and no public exploit code available. The vulnerability has received minor community discussion, but its EPSS score indicates a very low probability of exploitation in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.3.25CPE matchmatch criteria | cpe:2.3:a:endian:firewall_community:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.