Buffer Overflow Vulnerability in WatchGuard Fireware OS's DHCP Service
CVE-2026-81433
8.7HIGH
What is CVE-2026-81433?
A stack-based buffer overflow vulnerability exists in the DHCP fingerprinting daemon (fingerd) of WatchGuard Fireware OS, which could be exploited by an unauthenticated attacker with adjacent network access. By sending specially crafted DHCP packets, an attacker may execute arbitrary code or cause a crash of the process, leading to potential disruption of network services and exposing sensitive data.
Affected Version(s)
Fireware OS Default 2026.3 < 2026.3.2
Fireware OS Default 2025.0 < 2026.2.3
Fireware OS Default 12.0 < 12.12.3
References
CVSS V4
Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
Credit
Laurent GAFFIE, (secorizon.com)
