← לוח פגיעויות

CVE-2026-4266

בינונית 6.7

תיאור (מקור, אנגלית)

An Insecure Deserialization vulnerability in WatchGuard Fireware OS allows an attacker that has obtained write access to the local filesystem through another vulnerability to execute arbitrary code in the context of the portald user. Note, this vulnerability does not affect Firebox platforms that do not support the Access Portal feature, including the T15 and T35.

מדדים

CVSS 3.1
6.7 (MEDIUM) מקור הציון: NVD CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 4.0
8.4 (HIGH) מקור הציון: CNA CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS — סבירות ניצול
0% (אחוזון 000) נכון ל-24/9/2026
CWE
CWE-502

מוצרים מושפעים

watchguard: fireware; watchguard: firebox m295; watchguard: firebox m395; watchguard: firebox m495; watchguard: firebox m595; watchguard: firebox m695; watchguard: firebox t115-w; watchguard: firebox t125; watchguard: firebox t125-w; watchguard: firebox t145; watchguard: firebox t145-w; watchguard: firebox t185; watchguard: firebox cloud; watchguard: firebox m270; watchguard: firebox m290

קישורים