A NULL pointer dereference vulnerability in Fireware OS's NetFlow packet-processing feature allows a remote, unauthenticated attacker to cause a denial of service by sending a specially crafted IPv6 packet.
This vulnerability affects systems which have NetFlow enabled on an IPv6 path.
WatchGuard is not aware of any exploitation of this vulnerability in the wild.
Fireware OS 2026.3.2, Fireware OS 2026.2.3, Fireware OS 12.12.3, Fireware OS 12.5.21