Description
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS networkd process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the Management Web UI.
Published: 2026-07-02
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out‑of‑bounds write in the networkd process of WatchGuard Fireware OS (CWE‑787) allows an authenticated privileged user to execute arbitrary code by sending specially crafted requests to the Management Web UI. The flaw corrupts memory within the networkd service, enabling the attacker to gain the service’s privileges and potentially seize full control over the device’s network functions.

Affected Systems

The flaw affects all WatchGuard Fireware OS releases; patching is available in Fireware OS 2026.2.1, 12.12.1, and 12.5.19.

Risk and Exploitability

The CVSS score of 8.6 indicates significant risk. Exploitation requires an authenticated privileged user on the Management Web UI, who can send specially crafted requests to that interface, and network reachability to the UI. The vulnerability is not listed in CISA KEV. The EPSS score of less than 1 % indicates a low probability of widespread exploitation at present. The likely attack vector is network‑based; it relies on an attacker having privileged credentials or gaining them through compromise of a legitimate user session.

Generated by OpenCVE AI on August 10, 2026 at 23:42 UTC.

Remediation

Vendor Solution

Fireware OS 2026.2.1, Fireware OS 12.12.1, Fireware OS *, Fireware OS 12.5.19


OpenCVE Recommended Actions

  • Upgrade Fireware OS to any of the patched releases: 2026.2.1, 12.12.1, or 12.5.19.
  • Remove or restrict non‑essential privileged accounts on the Management Web UI.
  • Limit Management Web UI network access to trusted IP ranges or enforce secure VPN/SSL connections.

Generated by OpenCVE AI on August 10, 2026 at 23:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 10 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description An Out-of-bounds Write vulnerability in WatchGuard Fireware OS networkd process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the Management Web UI.This vulnerability affects Fireware OS 11.8 up to and including 11.12.4_Update1, 12.0 up to and including 12.12 and 2025.1 up to and including 2026.2. An Out-of-bounds Write vulnerability in WatchGuard Fireware OS networkd process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the Management Web UI.
CPEs cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:11.8
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.0
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.5
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:2025.1
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:*
References

Mon, 06 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Description An Out-of-bounds Write vulnerability in WatchGuard Fireware OS networkd process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the Management Web UI.This vulnerability affects Fireware OS 11.8 up to and including 11.12.4_Update1, 12.0 up to and including 12.12 and 2025.1 up to and including 2026.2.
Title WatchGuard Firebox networkd Out of Bounds Write Vulnerability
First Time appeared Watchguard
Watchguard fireware Os
Weaknesses CWE-787
CPEs cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:11.8
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.0
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.5
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:2025.1
Vendors & Products Watchguard
Watchguard fireware Os
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Watchguard Fireware Os
cve-icon MITRE

Status: PUBLISHED

Assigner: WatchGuard

Published:

Updated: 2026-08-10T19:23:48.865Z

Reserved: 2026-06-23T17:37:35.867Z

Link: CVE-2026-13050

cve-icon Vulnrichment

Updated: 2026-07-06T15:45:10.955Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-03T00:16:49.333

Modified: 2026-08-10T20:17:25.573

Link: CVE-2026-13050

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-10T23:45:04Z

Weaknesses