CVE-2026-81851: Fireware OS Heap-Based Buffer Overflow in iked Allows Denial of Service
A heap-based buffer overflow vulnerability in Fireware OS's iked process allows an authenticated administrator to crash the IKE daemon (iked), resulting in a denial of service, by saving a specially crafted configuration.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Fireware OS iked (IKE daemon)to a version that resolves this vulnerability.Fixed in 2026.2.1 - Upgrade
Upgrade
Fireware OS iked (IKE daemon)to a version that resolves this vulnerability.Fixed in 12.12.1 - Upgrade
Upgrade
Fireware OS iked (IKE daemon)to a version that resolves this vulnerability.Fixed in 12.11.9 - Upgrade
Upgrade
Fireware OS iked (IKE daemon)to a version that resolves this vulnerability.Fixed in 12.5.18
Event History
Frequently Asked Questions
Who can exploit this issue?
Exploitation requires an authenticated administrator who can save a specially crafted configuration. The issue affects the iked process in Fireware OS.
What is the operational impact of a successful exploit?
A successful exploit crashes the IKE daemon, iked, causing a denial of service. The provided information does not indicate code execution or impact beyond the daemon crash.
Is a default deployment exposed?
The provided information does not establish whether default configurations are affected. Exploitation depends on an authenticated administrator being able to save a crafted configuration.