Description
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to execute arbitrary code via a specially crafted CLI command.
Published: 2026-07-02
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out‑of‑bounds write flaw in WatchGuard Fireware OS’s command‑line interface allows an authenticated privileged user to craft a malicious CLI command that corrupts memory and executes arbitrary code. The weakness, identified as CWE-787, can grant the attacker full control over the device, compromising confidentiality, integrity and availability.

Affected Systems

The vulnerability affects Firebox devices running WatchGuard Fireware OS where the vulnerable CLI command handler is present. All firmware releases before the fixed versions—2026.2.1, 12.12.1 and 12.5.19—are potentially susceptible; devices that have not yet been upgraded should assume the flaw exists.

Risk and Exploitability

The CVSS score of 8.6 reflects high severity and the EPSS score of less than 1% indicates that exploitation is unlikely but still possible. The vulnerability is not in the CISA KEV catalog. Successful exploitation requires the attacker to authenticate with sufficient privileges to the management interface and submit the specially crafted CLI command to trigger the out‑of‑bounds write, after which code execution is achieved on the device.

Generated by OpenCVE AI on August 10, 2026 at 23:42 UTC.

Remediation

Vendor Solution

Fireware OS 2026.2.1, Fireware OS 12.12.1, Fireware OS *, Fireware OS 12.5.19


OpenCVE Recommended Actions

  • Upgrade to a patched release of WatchGuard Fireware OS, such as 2026.2.1, 12.12.1 or 12.5.19, as the vendor recommends.
  • Restrict management CLI access to trusted, privileged administrators and block or limit exposed management ports from external networks until the patch is applied.
  • If an immediate firmware upgrade is not feasible, disable or restrict the vulnerable CLI commands through configuration changes to reduce the attack surface, and monitor system logs for suspicious command usage.

Generated by OpenCVE AI on August 10, 2026 at 23:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 10 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to execute arbitrary code via a specially crafted CLI command. This vulnerability affects Fireware OS 11.0 up to and including 11.12.4_Update1, 12.0 up to and including 12.12 and 2025.1 up to and including 2026.2. An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to execute arbitrary code via a specially crafted CLI command.
CPEs cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:11.0
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.0
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.5
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:2025.1
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:*
References

Mon, 06 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Description An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to execute arbitrary code via a specially crafted CLI command. This vulnerability affects Fireware OS 11.0 up to and including 11.12.4_Update1, 12.0 up to and including 12.12 and 2025.1 up to and including 2026.2.
Title WatchGuard Firebox Authenticated Out of Bounds Write in Management CLI Command Handler
First Time appeared Watchguard
Watchguard fireware Os
Weaknesses CWE-787
CPEs cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:11.0
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.0
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.5
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:2025.1
Vendors & Products Watchguard
Watchguard fireware Os
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Watchguard Firebox M270 Firebox M290 Firebox M295 Firebox M370 Firebox M390 Firebox M395 Firebox M440 Firebox M4600 Firebox M470 Firebox M4800 Firebox M495 Firebox M5600 Firebox M570 Firebox M5800 Firebox M590 Firebox M595 Firebox M670 Firebox M690 Firebox M695 Firebox Nv5 Firebox T115-w Firebox T125 Firebox T125-w Firebox T145 Firebox T145-w Firebox T15 Firebox T185 Firebox T20 Firebox T25 Firebox T35 Firebox T40 Firebox T45 Firebox T55 Firebox T70 Firebox T80 Firebox T85 Fireboxcloud Fireboxv Fireware Fireware Os
cve-icon MITRE

Status: PUBLISHED

Assigner: WatchGuard

Published:

Updated: 2026-08-10T19:25:46.120Z

Reserved: 2026-06-23T17:49:03.096Z

Link: CVE-2026-13053

cve-icon Vulnrichment

Updated: 2026-07-06T14:52:10.496Z

cve-icon NVD

Status : Modified

Published: 2026-07-03T00:16:50.320

Modified: 2026-08-10T20:17:25.690

Link: CVE-2026-13053

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-10T23:45:04Z

Weaknesses