Description

A reflected cross-site scripting (XSS) vulnerability in the Fireware OS Web UI enabled execution of malicious JavaScript in the context of an authenticated management user's browser when they click on a specially crafted link. This vulnerability affects Fireware OS 12.7 up to and including 12.11.7 and 2025.1 up to and including 2026.1.1.

INFO

Published Date :

2026-03-03T13:17:48.810Z

Last Modified :

2026-03-04T15:22:22.283Z

Source :

WatchGuard
AFFECTED PRODUCTS

The following products are affected by CVE-2026-3343 vulnerability.

Vendors Products
Watchguard
  • Firebox M270
  • Firebox M290
  • Firebox M295
  • Firebox M370
  • Firebox M390
  • Firebox M395
  • Firebox M440
  • Firebox M4600
  • Firebox M470
  • Firebox M4800
  • Firebox M495
  • Firebox M5600
  • Firebox M570
  • Firebox M5800
  • Firebox M590
  • Firebox M595
  • Firebox M670
  • Firebox M690
  • Firebox M695
  • Firebox Nv5
  • Firebox T115-w
  • Firebox T125
  • Firebox T125-w
  • Firebox T145
  • Firebox T145-w
  • Firebox T185
  • Firebox T20
  • Firebox T25
  • Firebox T40
  • Firebox T45
  • Firebox T55
  • Firebox T70
  • Firebox T80
  • Firebox T85
  • Fireboxcloud
  • Fireboxv
  • Fireware
  • Fireware Os
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2026-3343.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact