CVE-2026-34790: Endian Firewall Community
High severity, CVSS 8.1. EPSS: 0.9% chance of exploitation in the next 30 days.
Endian Firewall version 3.3.25 and prior allow authenticated users to delete arbitrary files via directory traversal in the remove ARCHIVE parameter to /cgi-bin/backup.cgi. The remove ARCHIVE parameter value is used to construct a file path without sanitization of directory traversal sequences, which is then passed to an unlink() call.
Affected products
- Endian Firewall Community: up to and including 3.3.25
Published 2026-04-02. Last modified 2026-06-17.