Endian Firewall
cpe:2.3:a:endian:firewall:*:*:*:*:*:*:*
- <= 3.3.25
A command injection vulnerability has been identified in Endian Firewall versions through 3.3.25. This issue allows authenticated users to execute arbitrary operating system commands by manipulating the DATE parameter in the /cgi-bin/logs_smtp.cgi file. The vulnerability arises from inadequate regular expression validation, which enables the crafted parameter value to be used in a file path that is passed to a Perl open() function call, leading to command execution.
Exploitation of this vulnerability allows for arbitrary OS command execution on the affected system.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.