Impact
An out‑of‑bounds write in the networkd process of WatchGuard Fireware OS (CWE‑787) permits an authenticated privileged user to transmit to the Management Web UI, corrupting memory within the networkd service and enabling arbitrary code execution with the service’s privileges. This can result in full loss of control over the device’s network functions.
Affected Systems
The flaw affects all WatchGuard Fireware OS releases.8 up to and including 11.12.4 Update 1, 12.0 up to and including 12.12, and 2025.1 up to and including 2026.2. All releases are susceptible when the Management Web UI is reachable from a network that the attacker can access.
Risk and Exploitability
The CVSS score of 8.6 indicates significant risk. Exploitation requires an authenticated privileged user on the Management Web UI and network reachability to that interface. No publicly documented exploits exist and the vulnerability is not listed in CISA KEV. The EPSS score of less than 1 % indicates a low probability of widespread exploitation at present. The likely attack vector is network‑based; it relies on an attacker having privileged credentials or gaining them through compromise of a legitimate user session.
OpenCVE Enrichment