CVE-2015-5082: Endian Firewall
High severity, CVSS 10.0. EPSS: 69.9% chance of exploitation in the next 30 days.
Endian Firewall before 3.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) NEW_PASSWORD_1 or (2) NEW_PASSWORD_2 parameter to cgi-bin/chpasswd.cgi.
Affected products
- Endian Firewall Endian Firewall: up to and including 2.5.1
Published 2015-09-28. Last modified 2026-06-17.