Description
A path traversal vulnerability in the WatchGuard Fireware OS Management Web UI allows a privileged authenticated attacker to write arbitrary files on the Firebox's filesystem.
Published: 2026-07-02
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A path traversal flaw in the WatchGuard Fireware OS Management Web UI allows an attacker with privileged authentication to specify a relative file path that causes the system to write an arbitrary file to its filesystem. The vulnerability, classified as CWE‑22, permits the overwriting of critical system or configuration files, which could lead to loss of data integrity, denial of service, or enable further compromise of the device.

Affected Systems

The flaw affects WatchGuard Fireware OS releases that precede the patches identified in the CNA solution—specifically those earlier than Fireware OS 12.5.19, 12.12.1, and 2026.2.1.

Risk and Exploitability

The CVSS score of 8.6 indicates high severity. The EPSS score of less than 1% indicates a very low but non‑zero likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to be authenticated with privileged access to the Management Web UI; once that condition is satisfied, the attacker can supply a crafted file path to overwrite any file the web process can write to.

Generated by OpenCVE AI on August 10, 2026 at 23:09 UTC.

Remediation

Vendor Solution

Fireware OS 2026.2.1, Fireware OS 12.12.1, Fireware OS 12.5.19


OpenCVE Recommended Actions

  • Upgrade the Fireware OS to a release newer than 12.5.19, 12.12.1, or 2026.2.1 to eliminate the path traversal flaw.
  • If an upgrade cannot be performed immediately, limit access to the Management Web UI to trusted internal networks or local administrators, and block or tightly monitor external management sessions.
  • Enforce strict operating‑system file permissions on directories accessed by the web UI so that only authorized system processes can write, reducing the impact of any residual traversal attempts.

Generated by OpenCVE AI on August 10, 2026 at 23:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 10 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description A path traversal vulnerability in the WatchGuard Fireware OS Management Web UI allows a privileged authenticated attacker to write arbitrary files on the Firebox's filesystem. This vulnerability affects Fireware OS 11.0 up to and including 11.12.4_Update1, 12.0 up to and including 12.12 and 2025.1 up to and including 2026.2. A path traversal vulnerability in the WatchGuard Fireware OS Management Web UI allows a privileged authenticated attacker to write arbitrary files on the Firebox's filesystem.
CPEs cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:11.0
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.0
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.5
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:2025.1
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:*
References

Mon, 06 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Description A path traversal vulnerability in the WatchGuard Fireware OS Management Web UI allows a privileged authenticated attacker to write arbitrary files on the Firebox's filesystem. This vulnerability affects Fireware OS 11.0 up to and including 11.12.4_Update1, 12.0 up to and including 12.12 and 2025.1 up to and including 2026.2.
Title WatchGuard Firebox Arbitrary File Write via Path Traversal in Management Web UI
First Time appeared Watchguard
Watchguard fireware Os
Weaknesses CWE-22
CPEs cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:11.0
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.0
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.5
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:2025.1
Vendors & Products Watchguard
Watchguard fireware Os
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Watchguard Firebox M270 Firebox M290 Firebox M295 Firebox M370 Firebox M390 Firebox M395 Firebox M440 Firebox M4600 Firebox M470 Firebox M4800 Firebox M495 Firebox M5600 Firebox M570 Firebox M5800 Firebox M590 Firebox M595 Firebox M670 Firebox M690 Firebox M695 Firebox Nv5 Firebox T115-w Firebox T125 Firebox T125-w Firebox T145 Firebox T145-w Firebox T15 Firebox T185 Firebox T20 Firebox T25 Firebox T35 Firebox T40 Firebox T45 Firebox T55 Firebox T70 Firebox T80 Firebox T85 Fireboxcloud Fireboxv Fireware Fireware Os
cve-icon MITRE

Status: PUBLISHED

Assigner: WatchGuard

Published:

Updated: 2026-08-10T19:20:59.909Z

Reserved: 2026-06-23T17:55:06.157Z

Link: CVE-2026-13054

cve-icon Vulnrichment

Updated: 2026-07-06T15:45:40.439Z

cve-icon NVD

Status : Modified

Published: 2026-07-03T00:16:50.497

Modified: 2026-08-10T20:17:25.830

Link: CVE-2026-13054

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-10T23:15:05Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')