CVE-2026-18105: Fireware OS Uncontrolled Resource Consumption in Diagnostic Tasks Allows Denial of Service
An uncontrolled resource consumption vulnerability in Fireware OS's diagnostic tasks feature allows a low-privileged, authenticated user to cause a denial of service of the system's diagnostic tools by repeatedly starting and aborting a specially crafted diagnostic task through the web UI.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Fireware OSto a version that resolves this vulnerability.Fixed in 2026.3.2 - Upgrade
Upgrade
Fireware OSto a version that resolves this vulnerability.Fixed in 2026.2.3 - Upgrade
Upgrade
Fireware OSto a version that resolves this vulnerability.Fixed in 12.12.3 - Upgrade
Upgrade
Fireware OSto a version that resolves this vulnerability.Fixed in 12.5.21
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs a low-privileged authenticated account and access to the Fireware OS web UI. The issue is triggered through the diagnostic tasks feature.
What is the operational impact?
Repeatedly starting and aborting a specially crafted diagnostic task can deny service to the system's diagnostic tools. The provided information does not indicate that other Fireware OS functions are affected.
What attacker actions are required?
The attacker must repeatedly start and abort a specially crafted diagnostic task through the web interface. Authentication is required; the description does not describe unauthenticated exploitation.