Description
A path traversal vulnerability in the WatchGuard Fireware OS Management Web UI allows a privileged authenticated attacker to write arbitrary files on the Firebox's filesystem.




This vulnerability affects Fireware OS 11.0 up to and including 11.12.4_Update1, 12.0 up to and including 12.12 and 2025.1 up to and including 2026.2.
Published: 2026-07-02
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A path traversal flaw in the WatchGuard Fireware OS Management Web UI allows an attacker with privileged authentication to specify a relative file path that causes the system to write an arbitrary file to its filesystem. The vulnerability, classified as CWE‑22, permits the overwriting of critical system or configuration files, which could lead to loss of data integrity, denial of service, or enable further compromise of the device.

Affected Systems

The flaw affects WatchGuard Fireware OS releases 11.0 through 11.12.4 Update1, 12.0 through 12.12, and 2025.1 through 2026.2, meaning a wide range of Firebox hardware in production could be vulnerable if running an unpatched version.

Risk and Exploitability

The CVSS score of 8.6 marks this as a high‑severity issue. The EPSS score of less than 1% indicates a very low but non‑zero likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to be authenticated with privileged access to the Management Web UI; once that condition is satisfied, the attacker can supply a crafted file path to overwrite any file the web process can write to.

Generated by OpenCVE AI on July 21, 2026 at 10:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Fireware OS to a release newer than 11.12.4 Update1, 12.12, or 2026.2 to eliminate the path traversal flaw.
  • If an upgrade cannot be performed immediately, limit access to the Management Web UI to trusted internal networks or local administrators, and block or tightly monitor external management sessions.
  • Enforce strict operating‑system file permissions on directories accessed by the web UI so that only authorized system processes can write, reducing the impact of any residual traversal attempts.

Generated by OpenCVE AI on July 21, 2026 at 10:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Description A path traversal vulnerability in the WatchGuard Fireware OS Management Web UI allows a privileged authenticated attacker to write arbitrary files on the Firebox's filesystem. This vulnerability affects Fireware OS 11.0 up to and including 11.12.4_Update1, 12.0 up to and including 12.12 and 2025.1 up to and including 2026.2.
Title WatchGuard Firebox Arbitrary File Write via Path Traversal in Management Web UI
First Time appeared Watchguard
Watchguard fireware Os
Weaknesses CWE-22
CPEs cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:11.0
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.0
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.5
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:2025.1
Vendors & Products Watchguard
Watchguard fireware Os
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Watchguard Fireware Os
cve-icon MITRE

Status: PUBLISHED

Assigner: WatchGuard

Published:

Updated: 2026-07-07T03:56:23.074Z

Reserved: 2026-06-23T17:55:06.157Z

Link: CVE-2026-13054

cve-icon Vulnrichment

Updated: 2026-07-06T15:45:40.439Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T10:45:02Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')