Fireware OS 的 iked 进程中存在一个基于堆的缓冲区溢出漏洞。一个经过身份验证的 administrator(管理员)可以通过保存一个特制的配置文件来触发该漏洞,导致 IKE 守护进程(iked)崩溃,从而造成服务拒绝(DoS)。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| WatchGuard | Fireware OS | 2025.0< 2026.2.1 |
affected |
12.0< 12.12.1 |
affected | ||
12.0< 12.11.9 |
affected | ||
12.0< 12.5.18 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| WatchGuard | Fireware OS | 2025.0 ~ 2026.2.1 | - |
|
| WatchGuard | Fireware OS | 12.0 ~ 12.11.9 | - |
|
| WatchGuard | Fireware OS | 12.0 ~ 12.5.18 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-13086 | 9.3 CRITICAL | Fireware OS Stack-Based Buffer Overflow in Mobile Security epm Endpoint |
| CVE-2026-19318 | 9.3 CRITICAL | Fireware OS Pre-Authentication Stack Buffer Overflow in iked Allows Remote Code Execution |
| CVE-2026-78174 | 9.3 CRITICAL | WatchGuard Dimension Session Hijack via Exposed Session Tokens in Diagnostic Logs |
| CVE-2026-19313 | 9.3 CRITICAL | Fireware OS Pre-Authentication Heap Buffer Overflow in iked Allows Remote Code Execution |
| CVE-2026-19315 | 9.3 CRITICAL | Fireware OS Pre-Authentication Type Confusion in iked Allows Remote Code Execution |
| CVE-2026-19317 | 8.7 HIGH | Fireware OS Pre-Authentication Out-of-Bounds Read in iked Allows Denial of Service (DoS) |
| CVE-2026-78010 | 8.7 HIGH | Fireware OS Stack-Based Buffer Overflow in iked Allows Unauthenticated Denial of Service |
| CVE-2026-78011 | 8.7 HIGH | Fireware OS Integer Underflow in Iked Allows Unauthenticated Denial of Service (DoS) |
| CVE-2026-19316 | 8.7 HIGH | Fireware OS Pre-Authentication Double Free in iked Allows Denial of Service (DoS) |
| CVE-2026-19314 | 8.7 HIGH | Fireware OS Integer Underflow in iked Allows Unauthenticated Denial of Service (DoS) |
| CVE-2026-13108 | 8.7 HIGH | Dimension Denial-of-Service |
| CVE-2026-78009 | 8.7 HIGH | Fireware OS Out-of-Bounds Read in iked Allows Unauthenticated Denial of Service (DoS) |
| CVE-2026-78008 | 8.6 HIGH | Fireware OS Authenticated Buffer Overflow in wgagent |
| CVE-2026-78614 | 8.6 HIGH | Dimension SQL Injection in Audit Report |
| CVE-2026-78613 | 8.6 HIGH | Dimension SQL Injection in Log Viewer |
| CVE-2026-78612 | 8.6 HIGH | Dimension SQL Injection in Scheduled Report |
| CVE-2026-78610 | 8.4 HIGH | Dimension CSRF Vulnerability in Administrator Passphrase Change Endpoint |
| CVE-2026-78618 | 6.9 MEDIUM | Dimension Business Logic Flaw Allows Chained Backend Object Operations |
| CVE-2026-78617 | 6.3 MEDIUM | WatchGuard Dimension Web UI Authentication Brute-Force Due to Missing Rate Limiting |
| CVE-2026-78495 | 5.3 MEDIUM | Dimension Server-Side Request Forgery via Remote Backup Connection Test |
Showing top 20 of 28 CVEs. View all on vendor page → →
No comments yet