Impact
The vulnerability is a stack‑based buffer overflow in the Endpoint Protection Manager service used by the deprecated Mobile Security feature in WatchGuard Fireware OS. An unauthenticated remote attacker can exploit the flaw to execute arbitrary code on the device, potentially gaining full control of the operating system.
Affected Systems
WatchGuard Fireware OS appliances that include the Mobile Security (epm) service are affected. The issue exists in versions prior to the official fixes released in Fireware OS 2026.2.2, 12.12.2, and 12.5.20.
Risk and Exploitability
The CVSS score of 9.3 classifies this as a critical flaw. No EPSS score is available, so the likelihood of exploitation cannot be quantified from the data, but the flaw allows remote code execution without authentication, and it is not currently listed in CISA’s KEV catalog. The likely attack vector is a remote, unauthenticated client reaching the epm service over the network, which is inferred from the description.
OpenCVE Enrichment