CVE-2026-34793
- EPSS 0.49%
- Veröffentlicht 02.04.2026 14:45:49
- Zuletzt bearbeitet 07.04.2026 14:38:25
Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_firewall.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open() call, ...
CVE-2026-34792
- EPSS 0.49%
- Veröffentlicht 02.04.2026 14:45:48
- Zuletzt bearbeitet 07.04.2026 14:38:50
Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_clamav.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open() call, wh...
CVE-2026-34791
- EPSS 0.49%
- Veröffentlicht 02.04.2026 14:45:48
- Zuletzt bearbeitet 07.04.2026 14:39:06
Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_proxy.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open() call, whi...
CVE-2026-34790
- EPSS 0.16%
- Veröffentlicht 02.04.2026 14:45:47
- Zuletzt bearbeitet 07.04.2026 14:42:38
Endian Firewall version 3.3.25 and prior allow authenticated users to delete arbitrary files via directory traversal in the remove ARCHIVE parameter to /cgi-bin/backup.cgi. The remove ARCHIVE parameter value is used to construct a file path without s...
CVE-2021-27201
- EPSS 1.57%
- Veröffentlicht 15.02.2021 19:15:13
- Zuletzt bearbeitet 21.11.2024 05:57:34
Endian Firewall Community (aka EFW) 3.3.2 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in a backup comment.