Impact
An out-of-bounds write vulnerability in the WatchGuard Fireware OS wgagent process enables an authenticated privileged user to execute arbitrary code by sending a specially crafted request to the Management Web UI. The flaw is a classic out-of-bounds write (CWE-787) that causes the process to write beyond the bounds of a buffer, leading directly to arbitrary code execution on the device.
Affected Systems
The vulnerability affects WatchGuard Fireware OS devices that have not applied the vendor’s fixed releases. Any iteration of Fireware OS older than or not equal to the patched versions—2026.2.1, 12.12.1, or 12.5.19—remains vulnerable when the Management Web UI is enabled and accessed by an authenticated privileged user.
Risk and Exploitability
This flaw carries a CVSS score of 8.6, indicating high severity, while an EPSS score of <1 % reflects a low but non‑zero chance of exploitation. Because the exploit requires authenticated privileged access to the Management Web UI, attackers must compromise legitimate credentials or acquire administrative rights. The vulnerability is not listed in CISA KEV, but the potential for arbitrary code execution warrants proactive remediation.
OpenCVE Enrichment