Description
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to execute arbitrary code via a specially crafted CLI command.

This vulnerability affects Fireware OS 11.0 up to and including 11.12.4_Update1, 12.0 up to and including 12.12 and 2025.1 up to and including 2026.2.
Published: 2026-07-02
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out-of-bounds write flaw exists in the command line interface of WatchGuard Fireware OS. The vulnerability permits an attacker who has authenticated privileged access to the management interface to submit a specially crafted CLI command that corrupts memory and results in arbitrary code execution on the device. The flaw is categorized as CWE-787 and enables a clear confidentiality, integrity and availability impact on the affected appliance.

Affected Systems

The vulnerability affects WatchGuard Fireware OS versions 11.0 through 11.12.4_Update1, 12.0 through 12.12, and 2025.1 through 2026.2. These releases comprise the Fireware OS product line distributed by WatchGuard.

Risk and Exploitability

The CVSS score of 8.6 indicates a high severity vulnerability. The EPSS score of less than 1% indicates a very low but non‑zero probability of exploitation, and the flaw is not listed in the CISA KEV catalog. Exploitation requires the attacker to authenticate with sufficient privileges to the management interface, then submit a carefully crafted CLI command that triggers the out-of-bounds write. Successful exploitation would grant the attacker code execution rights on the device.

Generated by OpenCVE AI on July 21, 2026 at 10:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied firmware update that resolves the CLI out‑of‑bounds write flaw, as announced in the official advisory.
  • Enforce strong authentication and restrict the management interface to trusted IP ranges.
  • If an update cannot be applied immediately, disable the impacted CLI command or block the affected management ports to prevent exploitation.

Generated by OpenCVE AI on July 21, 2026 at 10:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Description An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to execute arbitrary code via a specially crafted CLI command. This vulnerability affects Fireware OS 11.0 up to and including 11.12.4_Update1, 12.0 up to and including 12.12 and 2025.1 up to and including 2026.2.
Title WatchGuard Firebox Authenticated Out of Bounds Write in Management CLI Command Handler
First Time appeared Watchguard
Watchguard fireware Os
Weaknesses CWE-787
CPEs cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:11.0
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.0
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.5
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:2025.1
Vendors & Products Watchguard
Watchguard fireware Os
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Watchguard Fireware Os
cve-icon MITRE

Status: PUBLISHED

Assigner: WatchGuard

Published:

Updated: 2026-07-07T03:56:17.670Z

Reserved: 2026-06-23T17:49:03.096Z

Link: CVE-2026-13053

cve-icon Vulnrichment

Updated: 2026-07-06T14:52:10.496Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T10:30:04Z

Weaknesses