CVE-2026-81433: Fireware OS Pre-Authentication Stack Buffer Overflow in fingerd Allows Remote Code Execution
Published Sep 29, 2026
·Updated
A stack-based buffer overflow vulnerability in WatchGuard Fireware OS's DHCP fingerprinting daemon (fingerd) allows an unauthenticated attacker with adjacent network access to execute arbitrary code or crash the process by sending a specially crafted DHCP packet.
Affected Software
1 affected component
WatchGuard Fireware OS
Event History
Sep 29, 2026
CVE Published
via MITRE·11:05 PM
Data Sourced
via MITRE·11:05 PM
RemedyDescriptionWeakness
Sep 30, 2026
Data Sourced
via NVD·12:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this vulnerability?
An unauthenticated attacker must have adjacent network access to the affected Fireware OS device. Exploitation is performed by sending a specially crafted DHCP packet to the DHCP fingerprinting daemon.
2
Is authentication required, and what could successful exploitation achieve?
No authentication is required. A successful attacker may execute arbitrary code or crash the fingerd process.