Impact
An out‑of‑bounds write flaw exists in the wgagent daemon that is accessed through the WatchGuard Fireware OS Management Web UI. A user who is authenticated with privileged rights can send a crafted request to the UI, causing the process to write beyond the bounds of a buffer and thereby gaining arbitrary code execution on the device. The weakness is a classic CWE‑787 out‑of‑bounds write that directly leads to remote code execution when the vulnerable component receives malicious input.
Affected Systems
The vulnerability affects WatchGuard Fireware OS, specifically versions 12.1 through 12.12 and 2025.1 through 2026.2. Devices running any of those releases with the Management Web UI enabled are at risk when accessed by authenticated users.
Risk and Exploitability
The CVSS score of 8.6 classifies this as high severity, while the EPSS score of <1% indicates a low but non‑zero likelihood of exploitation. Because the flaw requires authenticated privileged access, the risk is mitigated by limiting administrator access to the web UI and enforcing least privilege. The vulnerability is not listed in CISA KEV, but the potential for arbitrary code execution warrants prompt remediation.
OpenCVE Enrichment