Endian manufactures a focused line of firewall and gateway appliances serving small-to-medium enterprises and branch offices, a category that enjoys prominence in mid-market network deployments despite a narrow product range. The vendor's vulnerability exposure recurs through web-interface and system-command processing pathways, manifesting repeatedly as cross-site scripting, OS command injection, and path-traversal flaws that are typical of management-tier and administrative components in embedded appliances. These weakness classes reflect the challenge of securing heterogeneous input sources and privilege boundaries within a unified gateway product family. Defenders should prioritize management-interface isolation and access controls for this vendor's products and monitor administrative functionality patches closely; current severity, exploitation activity, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Endian over time
Signals from CVEs in this vendor scope (37 CVEs).
37 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-34797HIGH Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_smtp.cgi. The DATE parameter value is us | Apr 2, 2026 | 8.8 | 31 | NO | NO |
CVE-2026-34796HIGH Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_openvpn.cgi. The DATE parameter value is | Apr 2, 2026 | 8.8 | 31 | NO | NO |
CVE-2026-34795HIGH Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_log.cgi. The DATE parameter value is use | Apr 2, 2026 | 8.8 | 31 | NO | NO |
CVE-2026-34794HIGH Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_ids.cgi. The DATE parameter value is use | Apr 2, 2026 | 8.8 | 31 | NO | NO |
CVE-2026-34792HIGH Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_clamav.cgi. The DATE parameter value is | Apr 2, 2026 | 8.8 | 31 | NO | NO |
CVE-2026-34793HIGH Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_firewall.cgi. The DATE parameter value i | Apr 2, 2026 | 8.8 | 30 | NO | NO |
CVE-2026-34791HIGH Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_proxy.cgi. The DATE parameter value is u | Apr 2, 2026 | 8.8 | 30 | NO | NO |
CVE-2021-27201HIGH Endian Firewall Community (aka EFW) 3.3.2 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in a backup comment. | Feb 15, 2021 | 8.8 | 28 | NO | NO |
CVE-2026-34790HIGH Endian Firewall version 3.3.25 and prior allow authenticated users to delete arbitrary files via directory traversal in the remove ARCHIVE parameter to /cgi-bin/backup.cgi. The rem | Apr 2, 2026 | 8.1 | 26 | NO | NO |
CVE-2012-4923MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Endian Firewall 2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) createrule parameter to dnat.cg | Sep 15, 2012 | 4.3 | 24 | NO | YES |
Signals from CVEs in this vendor scope (37 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Endian.
Media articles that mention a CVE ID that affects a product developed by Endian — matched by CVE ID, not by vendor name.