Impact
An authenticated administrator can trigger a denial-of-service condition in the Fireware Management Web UI by sending malformed or crafted data to the put_data endpoint, which performs unsafe deserialization of attacker-supplied input. The deserialization flaw allows the application to read corrupted data structures, causing the web UI to crash or become unresponsive. The result is a loss of administrative control over the device. The impact is limited to availability and does not provide direct access to confidential information or system integrity.
Affected Systems
The vulnerability affects WatchGuard Fireware OS versions 12.0, 12.5, and 2025.1. The flaw resides in the management web UI component of these firmware releases, and an administrator must use the web interface to trigger it.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, while the EPSS score of <1 % demonstrates a very low likelihood of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the attack requires administrator authentication and can be carried out over the web interface by sending malformed POST requests to the put_data endpoint. No additional privileges are necessary, and the flaw does not allow escalation of privileges or compromise of confidentiality.
OpenCVE Enrichment