---
id: CVE-2026-34795
title: >-
  Endian Firewall version 3.3.25 and prior allow authenticated users to execute
  arbitrary OS commands via the DATE parameter to /cgi-bin/logs_log.cgi
summary: >-
  Endian Firewall version 3.3.25 and prior allow authenticated users to execute
  arbitrary OS commands via the DATE parameter to /cgi-bin/logs_log.cgi. The
  DATE parameter value is used to construct a file path that is passed to a Perl
  open(…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-78
vendor: endian
product: firewall_community
affected:
  - firewall_community <= 3.3.25
published: '2026-04-02'
updated: '2026-07-24'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-34795'
references:
  - url: 'https://help.endian.com/hc/en-us/sections/360004371358-Community'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/endian-firewall-cgi-bin-logs-log-cgi-date-perl-command-injection
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.01469
epssPercentile: 0.7262
ingestedAt: '2026-07-25T21:03:58.211Z'
---

## Overview

Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_log.cgi. The DATE parameter value is used to construct a file path that is passed to a Perl open() call, which allows command injection due to an incomplete regular expression validation.

## Affected

- `firewall_community <= 3.3.25`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
