CVE-2026-34790
EUVD-2026-1826202.04.2026, 15:16
Endian Firewall version 3.3.25 and prior allow authenticated users to delete arbitrary files via directory traversal in the remove ARCHIVE parameter to /cgi-bin/backup.cgi. The remove ARCHIVE parameter value is used to construct a file path without sanitization of directory traversal sequences, which is then passed to an unlink() call.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| endian | firewall_community | 𝑥 ≤ 3.3.25 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| endian | firewall | 3.3.25 | CNA |