wgagent 管理守护进程的会话初始化函数中存在一个缺失授权检查的漏洞。该漏洞允许经过认证的低权限用户(包括只读或访客管理员账户)通过提交特制的管理 API 请求,导致 wgagent 进程崩溃,并读取该守护进程有权访问的任意文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| WatchGuard | Fireware OS | 2026.0 ~ 2026.3.2 | - |
|
| WatchGuard | Fireware OS | 12.0 ~ 12.5.21 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86131 | 9.2 CRITICAL | Fireware OS Code Injection in BOVPN Over TLS Client Allows Remote Code Execution |
| CVE-2026-81433 | 8.7 HIGH | Fireware OS Pre-Authentication Stack Buffer Overflow in fingerd Allows Remote Code Executi |
| CVE-2026-86104 | 8.7 HIGH | Fireware OS Resource Exhaustion in Login Process Allows Denial of Service |
| CVE-2026-18145 | 8.6 HIGH | Fireware OS Stack-based Buffer Overflow in spamd Allows Remote Code Execution |
| CVE-2026-13224 | 8.2 HIGH | Fireware OS Path Traversal in WebUI Management Agent Allows Arbitrary Local File Read |
| CVE-2026-86128 | 8.2 HIGH | Fireware OS NULL Pointer Dereference in NetFlow IPv6 Traffic Processing Allows Remote Deni |
| CVE-2026-86132 | 8.2 HIGH | Fireware OS Pre-Authentication Integer Underflow in iked Allows Denial of Service |
| CVE-2026-86133 | 8.2 HIGH | Fireware OS Pre-Authentication Integer Underflow in iked Allows Remote Denial of Service |
| CVE-2026-13046 | 7.5 HIGH | Fireware OS Deserialization of Untrusted Data in samld Allows Remote Code Execution |
| CVE-2026-86101 | 7.2 HIGH | Fireware OS Authorization Bypass in SAML Login Allows Unauthorized SSLVPN Access |
| CVE-2026-90441 | 7.1 HIGH | Fireware OS Missing Authorization in wgagent Management API Allows Denial of Service - Var |
| CVE-2026-18105 | 7.1 HIGH | Fireware OS Uncontrolled Resource Consumption in Diagnostic Tasks Allows Denial of Service |
| CVE-2026-86105 | 5.3 MEDIUM | Fireware OS Improper Authorization in Access Portal Reverse Proxy |
No comments yet