Description
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS wgagent process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the Management Web UI.This vulnerability affects Fireware OS 12.1 up to and including 12.12 and 2025.1 up to and including 2026.2.
Published: 2026-07-02
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out‑of‑bounds write flaw exists in the wgagent daemon that is accessed through the WatchGuard Fireware OS Management Web UI. A user who is authenticated with privileged rights can send a crafted request to the UI, causing the process to write beyond the bounds of a buffer and thereby gaining arbitrary code execution on the device. The weakness is a classic CWE‑787 out‑of‑bounds write that directly leads to remote code execution when the vulnerable component receives malicious input.

Affected Systems

The vulnerability affects WatchGuard Fireware OS, specifically versions 12.1 through 12.12 and 2025.1 through 2026.2. Devices running any of those releases with the Management Web UI enabled are at risk when accessed by authenticated users.

Risk and Exploitability

The CVSS score of 8.6 classifies this as high severity, while the EPSS score of <1% indicates a low but non‑zero likelihood of exploitation. Because the flaw requires authenticated privileged access, the risk is mitigated by limiting administrator access to the web UI and enforcing least privilege. The vulnerability is not listed in CISA KEV, but the potential for arbitrary code execution warrants prompt remediation.

Generated by OpenCVE AI on July 22, 2026 at 13:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the device to the latest Fireware OS firmware that incorporates the fix for this vulnerability.
  • Restrict access to the Management Web UI by limiting connections to a secure internal network or VPN and blocking it from public or untrusted networks.
  • Apply strict role‑based access controls so that only designated administrators can authenticate to the web UI, and monitor authentication logs for suspicious activity.

Generated by OpenCVE AI on July 22, 2026 at 13:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Description An Out-of-bounds Write vulnerability in WatchGuard Fireware OS wgagent process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the Management Web UI.This vulnerability affects Fireware OS 12.1 up to and including 12.12 and 2025.1 up to and including 2026.2.
Title WatchGuard Firebox wgagent Out of Bounds Write Vulnerability
First Time appeared Watchguard
Watchguard fireware Os
Weaknesses CWE-787
CPEs cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.1
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.5
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:2025.1
Vendors & Products Watchguard
Watchguard fireware Os
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Watchguard Fireware Os
cve-icon MITRE

Status: PUBLISHED

Assigner: WatchGuard

Published:

Updated: 2026-07-07T03:56:37.194Z

Reserved: 2026-06-25T22:44:10.384Z

Link: CVE-2026-13384

cve-icon Vulnrichment

Updated: 2026-07-06T14:32:53.936Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-22T13:30:05Z

Weaknesses