CVE-2026-4266
בינונית 6.7
תיאור (מקור, אנגלית)
An Insecure Deserialization vulnerability in WatchGuard Fireware OS allows an attacker that has obtained write access to the local filesystem through another vulnerability to execute arbitrary code in the context of the portald user. Note, this vulnerability does not affect Firebox platforms that do not support the Access Portal feature, including the T15 and T35.
מדדים
- CVSS 3.1
-
6.7 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H - CVSS 4.0
-
8.4 (HIGH)
מקור הציון: CNA
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-24/9/2026
- CWE
- CWE-502
מוצרים מושפעים
watchguard: fireware; watchguard: firebox m295; watchguard: firebox m395; watchguard: firebox m495; watchguard: firebox m595; watchguard: firebox m695; watchguard: firebox t115-w; watchguard: firebox t125; watchguard: firebox t125-w; watchguard: firebox t145; watchguard: firebox t145-w; watchguard: firebox t185; watchguard: firebox cloud; watchguard: firebox m270; watchguard: firebox m290
קישורים
- https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00007 Vendor Advisory
- https://psirt.watchguard.com/CVE-2026-4266 Broken Link