A vulnerability marked as problematic has been reported in Endian Firewall 3.3.25. Affected is an unknown function of the file /manage/password/web/ of the component Parameter Handler. This manipulation of the argument remark causes cross site scripting.

This vulnerability is registered as CVE-2026-34823. Remote exploitation of the attack is possible. No exploit is available.