Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Endian

First CVE: Jan 30, 2008Active for: 18 yearsTotal CVEs: 37
24.2
VTI Score
Low

Endian manufactures a focused line of firewall and gateway appliances serving small-to-medium enterprises and branch offices, a category that enjoys prominence in mid-market network deployments despite a narrow product range. The vendor's vulnerability exposure recurs through web-interface and system-command processing pathways, manifesting repeatedly as cross-site scripting, OS command injection, and path-traversal flaws that are typical of management-tier and administrative components in embedded appliances. These weakness classes reflect the challenge of securing heterogeneous input sources and privilege boundaries within a unified gateway product family. Defenders should prioritize management-interface isolation and access controls for this vendor's products and monitor administrative functionality patches closely; current severity, exploitation activity, and exposure metrics are shown alongside this summary.

FAUCET AI Generated
37
Total CVEs
More Total CVEs than 98% of tracked vendors
4.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 48% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Endian over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 30, 2008
18 years ago
Most Recent CVE
Apr 2, 2026
113 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (37 CVEs).

37 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-34797HIGH
Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_smtp.cgi. The DATE parameter value is us
Apr 2, 20268.831NONO
CVE-2026-34796HIGH
Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_openvpn.cgi. The DATE parameter value is
Apr 2, 20268.831NONO
CVE-2026-34795HIGH
Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_log.cgi. The DATE parameter value is use
Apr 2, 20268.831NONO
CVE-2026-34794HIGH
Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_ids.cgi. The DATE parameter value is use
Apr 2, 20268.831NONO
CVE-2026-34792HIGH
Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_clamav.cgi. The DATE parameter value is
Apr 2, 20268.831NONO
CVE-2026-34793HIGH
Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_firewall.cgi. The DATE parameter value i
Apr 2, 20268.830NONO
CVE-2026-34791HIGH
Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_proxy.cgi. The DATE parameter value is u
Apr 2, 20268.830NONO
CVE-2021-27201HIGH
Endian Firewall Community (aka EFW) 3.3.2 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in a backup comment.
Feb 15, 20218.828NONO
CVE-2026-34790HIGH
Endian Firewall version 3.3.25 and prior allow authenticated users to delete arbitrary files via directory traversal in the remove ARCHIVE parameter to /cgi-bin/backup.cgi. The rem
Apr 2, 20268.126NONO
CVE-2012-4923MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in Endian Firewall 2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) createrule parameter to dnat.cg
Sep 15, 20124.324NOYES
View all 37 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products37 CVEs
76%
24%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network35 (94.6%)
Unknown2 (5.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low35 (94.6%)
High0 (0.0%)
Unknown2 (5.4%)
User Interaction
None35 (94.6%)
Unknown2 (5.4%)
Required0 (0.0%)
Privileges Required
Low35 (94.6%)
High0 (0.0%)
None0 (0.0%)
Unknown2 (5.4%)

Exploit Exposure

Signals from CVEs in this vendor scope (37 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
2.7% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Endian.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Endian — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Endian's Products

View all 2 CNAs →

Top CWEs