Description
A type confusion vulnerability in the iked process of WatchGuard Fireware OS allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Fireware OS 2026.2.2, Fireware OS 12.12.2, Fireware OS 12.5.20
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://psirt.watchguard.com/CVE-2026-19315 |
|
History
Thu, 27 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A type confusion vulnerability in the iked process of WatchGuard Fireware OS allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic. | |
| Title | Fireware OS Pre-Authentication Type Confusion in iked Allows Remote Code Execution | |
| First Time appeared |
Watchguard
Watchguard fireware Os |
|
| Weaknesses | CWE-125 CWE-763 CWE-843 |
|
| CPEs | cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Watchguard
Watchguard fireware Os |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: WatchGuard
Published:
Updated: 2026-08-27T23:24:33.721Z
Reserved: 2026-08-07T20:05:56.818Z
Link: CVE-2026-19315
No data.
Status : Received
Published: 2026-08-28T02:16:20.703
Modified: 2026-08-28T02:16:20.703
Link: CVE-2026-19315
No data.
OpenCVE Enrichment
Updated: 2026-08-28T05:45:04Z