Impact
A path traversal flaw in the WatchGuard Fireware OS Management Web UI allows an attacker with privileged authentication to specify a relative file path that causes the system to write an arbitrary file to its filesystem. The vulnerability, classified as CWE‑22, permits the overwriting of critical system or configuration files, which could lead to loss of data integrity, denial of service, or enable further compromise of the device.
Affected Systems
The flaw affects WatchGuard Fireware OS releases 11.0 through 11.12.4 Update1, 12.0 through 12.12, and 2025.1 through 2026.2, meaning a wide range of Firebox hardware in production could be vulnerable if running an unpatched version.
Risk and Exploitability
The CVSS score of 8.6 marks this as a high‑severity issue. The EPSS score of less than 1% indicates a very low but non‑zero likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to be authenticated with privileged access to the Management Web UI; once that condition is satisfied, the attacker can supply a crafted file path to overwrite any file the web process can write to.
OpenCVE Enrichment