Description
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS networkd process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the Management Web UI.This vulnerability affects Fireware OS 11.8 up to and including 11.12.4_Update1, 12.0 up to and including 12.12 and 2025.1 up to and including 2026.2.
Published: 2026-07-02
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out‑of‑bounds write in the networkd process of WatchGuard Fireware OS (CWE‑787) permits an authenticated privileged user to transmit to the Management Web UI, corrupting memory within the networkd service and enabling arbitrary code execution with the service’s privileges. This can result in full loss of control over the device’s network functions.

Affected Systems

The flaw affects all WatchGuard Fireware OS releases.8 up to and including 11.12.4 Update 1, 12.0 up to and including 12.12, and 2025.1 up to and including 2026.2. All releases are susceptible when the Management Web UI is reachable from a network that the attacker can access.

Risk and Exploitability

The CVSS score of 8.6 indicates significant risk. Exploitation requires an authenticated privileged user on the Management Web UI and network reachability to that interface. No publicly documented exploits exist and the vulnerability is not listed in CISA KEV. The EPSS score of less than 1 % indicates a low probability of widespread exploitation at present. The likely attack vector is network‑based; it relies on an attacker having privileged credentials or gaining them through compromise of a legitimate user session.

Generated by OpenCVE AI on July 21, 2026 at 10:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Fireware OS to a version that includes the fix for the networkd out‑of‑bounds write.
  • Restrict or remove privileged accounts on the Management Web UI that are not required for day‑to‑day management.
  • Limit network access to the Management Web UI to trusted IP ranges or enforce VPN/SSL connections.

Generated by OpenCVE AI on July 21, 2026 at 10:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Description An Out-of-bounds Write vulnerability in WatchGuard Fireware OS networkd process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the Management Web UI.This vulnerability affects Fireware OS 11.8 up to and including 11.12.4_Update1, 12.0 up to and including 12.12 and 2025.1 up to and including 2026.2.
Title WatchGuard Firebox networkd Out of Bounds Write Vulnerability
First Time appeared Watchguard
Watchguard fireware Os
Weaknesses CWE-787
CPEs cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:11.8
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.0
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.5
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:2025.1
Vendors & Products Watchguard
Watchguard fireware Os
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Watchguard Fireware Os
cve-icon MITRE

Status: PUBLISHED

Assigner: WatchGuard

Published:

Updated: 2026-07-07T03:56:20.933Z

Reserved: 2026-06-23T17:37:35.867Z

Link: CVE-2026-13050

cve-icon Vulnrichment

Updated: 2026-07-06T15:45:10.955Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T10:45:02Z

Weaknesses