Impact
The flaw is a stored cross‑site scripting vulnerability in Endian Firewall that allows an authenticated attacker to inject arbitrary JavaScript into the remark field of the DHCP fixed leases management page. When other users view the page, the malicious script is executed, potentially compromising their browsing session. The weakness is classified as CWE‑79.
Affected Systems
This issue affects Endian Firewall products, including version 3.3.25 and all earlier releases such as 2.1.2, 2.4, the 3.3 series prior to 3.3.25, and the community edition. It is triggered through the remark parameter of the /manage/dhcp/fixed_leases/ endpoint.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation. It is not listed in the CISA KEV catalog. The likely attack vector requires the attacker to be an authenticated user who submits a malicious remark; the payload is then stored and delivered to other authenticated or unauthenticated users who view the page.
OpenCVE Enrichment