Impact
An out-of-bounds write flaw exists in the command line interface of WatchGuard Fireware OS. The vulnerability permits an attacker who has authenticated privileged access to the management interface to submit a specially crafted CLI command that corrupts memory and results in arbitrary code execution on the device. The flaw is categorized as CWE-787 and enables a clear confidentiality, integrity and availability impact on the affected appliance.
Affected Systems
The vulnerability affects WatchGuard Fireware OS versions 11.0 through 11.12.4_Update1, 12.0 through 12.12, and 2025.1 through 2026.2. These releases comprise the Fireware OS product line distributed by WatchGuard.
Risk and Exploitability
The CVSS score of 8.6 indicates a high severity vulnerability. The EPSS score of less than 1% indicates a very low but non‑zero probability of exploitation, and the flaw is not listed in the CISA KEV catalog. Exploitation requires the attacker to authenticate with sufficient privileges to the management interface, then submit a carefully crafted CLI command that triggers the out-of-bounds write. Successful exploitation would grant the attacker code execution rights on the device.
OpenCVE Enrichment