CVE-2026-3342 PUBLISHED

WatchGuard Firebox Out of Bounds Write Vulnerability

Assigner: WatchGuard
Reserved: 27.02.2026 Published: 03.03.2026 Updated: 03.03.2026

An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow an authenticated privileged administrator to execute arbitrary code with root permissions via an exposed management interface.

This vulnerability affects Fireware OS 11.9 up to and including 11.12.4_Update1, 12.0 up to and including 12.11.7 and 2025.1 up to and including 2026.1.1.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.6

Product Status

Vendor WatchGuard
Product Fireware OS
Versions Default: unaffected
  • affected from 11.9 to 11.12.4+541730 (incl.)
  • affected from 12.0 to 12.11.7 (incl.)
  • affected from 12.5 to 12.5.16 (incl.)
  • affected from 2025.1 to 2026.1.1 (incl.)

Exploits

WatchGuard is not aware of any exploitation of this issue in the wild.

Credits

  • btaol finder

References

Problem Types

  • CWE-787 Out-of-bounds Write CWE

Impacts

  • CAPEC-253 Remote Code Inclusion