A code injection vulnerability in WatchGuard Fireware OS's BOVPN Over TLS client configuration handling allows an attacker who controls the remote VPN server to execute arbitrary commands as root on the connecting Firebox.
Advisories
No advisories yet.
Fixes
Solution
Fireware OS 2026.3.2, Fireware OS 2026.2.3, Fireware OS 12.12.3, Fireware OS 12.5.21
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://psirt.watchguard.com/CVE-2026-86131 |
|
History
Tue, 29 Sep 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A code injection vulnerability in WatchGuard Fireware OS's BOVPN Over TLS client configuration handling allows an attacker who controls the remote VPN server to execute arbitrary commands as root on the connecting Firebox. | |
| Title | Fireware OS Code Injection in BOVPN Over TLS Client Allows Remote Code Execution | |
| First Time appeared |
Watchguard
Watchguard fireware Os |
|
| Weaknesses | CWE-295 CWE-829 CWE-94 |
|
| CPEs | cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Watchguard
Watchguard fireware Os |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WatchGuard
Published:
Updated: 2026-09-29T23:05:47.700Z
Reserved: 2026-09-05T02:50:33.788Z
Link: CVE-2026-86131
No data.
Status : Received
Published: 2026-09-30T00:16:36.817
Modified: 2026-09-30T00:16:36.817
Link: CVE-2026-86131
No data.
OpenCVE Enrichment
Updated: 2026-09-30T01:00:09Z