CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 7.1. Exploitation may require the attacker to be authenticated.
CVE
CVE-2026-34790
Severity
HIGH
CVSS
7.1
EPSS
0.63%
Original NVD Description
Endian Firewall version 3.3.25 and prior allow authenticated users to delete arbitrary files via directory traversal in the remove ARCHIVE parameter to /cgi-bin/backup.cgi. The remove ARCHIVE parameter value is used to construct a file path without sanitization of directory traversal sequences, which is then passed to an unlink() call.
Related CVEs
Other vulnerabilities affecting the same vendor(s)