Description
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS ikestubd process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the Management Web UI.
Published: 2026-07-02
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out‑of‑bounds write flaw exists in the WatchGuard Fireware OS ikestubd service. The vulnerability is triggered by a specially crafted request sent to the Management Web UI. The memory corruption allows an authenticated privileged user to execute arbitrary code on the device with the privileges of the ikestubd process. This can compromise confidentiality, integrity, and availability of the system. The weakness is classified as CWE‑787.

Affected Systems

Affected systems are not specifically enumerated in the CVE data; the vulnerability applies to WatchGuard Fireware OS components that include the ikestubd process and expose the Management Web UI.

Risk and Exploitability

The CVSS score of 8.6 indicates high severity. The EPSS score of less than 1% suggests a low but measurable likelihood of exploitation. The flaw is not listed in CISA’s KEV catalog, meaning no public exploits are known. Exploitation requires an authenticated privileged user with access to the Management Web UI; unauthenticated remote attack is not possible.

Generated by OpenCVE AI on August 10, 2026 at 23:11 UTC.

Remediation

Vendor Solution

Fireware OS 2026.2.1, Fireware OS 12.12.1, Fireware OS 12.5.19


OpenCVE Recommended Actions

  • Upgrade to Fireware OS 2026.2.1, Fireware OS 12.12.1, or Fireware OS 12.5.19 per the vendor advisories
  • Restrict privileged accounts that can access the Management Web UI
  • Enforce multi‑factor authentication for all privileged UI access
  • Limit or disable the Management Web UI to trusted IP ranges or a dedicated management network
  • Monitor system logs for anomalous ikestubd activity

Generated by OpenCVE AI on August 10, 2026 at 23:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 10 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Description An Out-of-bounds Write vulnerability in WatchGuard Fireware OS ikestubd process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the Management Web UI.This vulnerability affects Fireware OS 12.1 up to and including 12.12 and 2025.1 up to and including 2026.2. An Out-of-bounds Write vulnerability in WatchGuard Fireware OS ikestubd process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the Management Web UI.
CPEs cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.1
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.5
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:2025.1
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:*
References

Mon, 06 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Description An Out-of-bounds Write vulnerability in WatchGuard Fireware OS ikestubd process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the Management Web UI.This vulnerability affects Fireware OS 12.1 up to and including 12.12 and 2025.1 up to and including 2026.2.
Title WatchGuard Firebox ikestubd Out of Bounds Write Vulnerability
First Time appeared Watchguard
Watchguard fireware Os
Weaknesses CWE-787
CPEs cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.1
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.5
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:2025.1
Vendors & Products Watchguard
Watchguard fireware Os
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Watchguard Firebox M270 Firebox M290 Firebox M295 Firebox M370 Firebox M390 Firebox M395 Firebox M440 Firebox M4600 Firebox M470 Firebox M4800 Firebox M495 Firebox M5600 Firebox M570 Firebox M5800 Firebox M590 Firebox M595 Firebox M670 Firebox M690 Firebox M695 Firebox Nv5 Firebox T115-w Firebox T125 Firebox T125-w Firebox T145 Firebox T145-w Firebox T15 Firebox T185 Firebox T20 Firebox T25 Firebox T35 Firebox T40 Firebox T45 Firebox T55 Firebox T70 Firebox T80 Firebox T85 Fireboxcloud Fireboxv Fireware Fireware Os
cve-icon MITRE

Status: PUBLISHED

Assigner: WatchGuard

Published:

Updated: 2026-08-10T17:23:58.571Z

Reserved: 2026-06-25T22:44:09.033Z

Link: CVE-2026-13383

cve-icon Vulnrichment

Updated: 2026-07-06T14:32:03.370Z

cve-icon NVD

Status : Modified

Published: 2026-07-03T00:16:51.773

Modified: 2026-08-10T18:17:40.590

Link: CVE-2026-13383

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-10T23:15:05Z

Weaknesses