A code injection vulnerability in WatchGuard Fireware OS's BOVPN Over TLS client configuration handling allows an attacker who controls the remote VPN server to execute arbitrary commands as root on the connecting Firebox.
Score CVSS v3.1
9.8
/ 10.0
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Informations
- Publié
- 30 sept. 2026
- Mis à jour
- 6 oct. 2026
- Statut
- Analyzed
- Source
- 5d1c2695-1a31-4499-88ae-e847036fd7e3
Produits affectés
watchguard fireware
Versions : 12.5.21, 12.12.3, 2026.2.3, 2026.3.2
Faiblesses (CWE)
CWE-94CWE-295CWE-829
Références (1)
- https://psirt.watchguard.com/CVE-2026-86131PatchVendor Advisory
CVEs similaires
Autres vulnérabilités de type CWE-94
Loading…
Surveillez vos produits
Recevez une alerte automatique à chaque nouvelle CVE affectant vos équipements.