Description
WatchGuard Fireware OS contains a firmware validation bypass when processing a backup image via the backup/restore feature. An authenticated administrator can exploit this vulnerability to install a tampered firmware image.
Published: 2026-07-02
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

WatchGuard Fireware OS contains a firmware validation bypass when processing a backup image via the backup/restore feature. An authenticated administrator who uploads a tampered firmware image will be accepted because the integrity check is circumvented, allowing the installation of arbitrary firmware. This can lead to full device compromise with malicious code executed on the appliance.

Affected Systems

WatchGuard Fireware OS is affected. Devices running any firmware version that has not yet incorporated the security update delivered in Fireware OS 2026.2.1 or Fireware OS 12.12.1 are vulnerable. The backup/restore feature is the entry point, so any appliance that supports this functionality and runs an earlier release is at risk.

Risk and Exploitability

The CVSS score of 8.6 marks this vulnerability as high severity, while the EPSS score of less than 1% indicates a low current likelihood of exploitation. Because the attack requires authenticated administrator credentials, an attacker would need to compromise or spoof those credentials before uploading a malicious firmware image via the backup/restore interface. The vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known exploits yet.

Generated by OpenCVE AI on August 10, 2026 at 23:10 UTC.

Remediation

Vendor Solution

Fireware OS 2026.2.1, Fireware OS 12.12.1


OpenCVE Recommended Actions

  • Upgrade all affected devices to Fireware OS 2026.2.1 or Fireware OS 12.12.1, which includes the firmware validation fix.
  • If an immediate upgrade is not feasible, restrict use of the backup/restore feature to trusted administrators only and consider disabling the feature entirely until the patch is deployed.
  • Strengthen administrative account security by enforcing multi‑factor authentication and limiting the number of privileged accounts.
  • Regularly verify the integrity of installed firmware and monitor backup/restore logs for suspicious uploads.

Generated by OpenCVE AI on August 10, 2026 at 23:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 10 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description WatchGuard Fireware OS contains a firmware validation bypass when processing a backup image via the backup/restore feature. An authenticated administrator can exploit this vulnerability to install a tampered firmware image.This vulnerability affects Fireware OS 11.0 up to and including 11.12.4_Update1, 12.0 up to and including 12.12 and 2025.1 up to and including 2025.6.2. WatchGuard Fireware OS contains a firmware validation bypass when processing a backup image via the backup/restore feature. An authenticated administrator can exploit this vulnerability to install a tampered firmware image.
CPEs cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:11.0
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.0
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.5
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:2025.1
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:*
References

Mon, 06 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Description WatchGuard Fireware OS contains a firmware validation bypass when processing a backup image via the backup/restore feature. An authenticated administrator can exploit this vulnerability to install a tampered firmware image.This vulnerability affects Fireware OS 11.0 up to and including 11.12.4_Update1, 12.0 up to and including 12.12 and 2025.1 up to and including 2025.6.2.
Title WatchGuard Firebox Firmware Image Validation Bypass in WatchGuard Fireware OS
First Time appeared Watchguard
Watchguard fireware Os
Weaknesses CWE-347
CPEs cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:11.0
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.0
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.5
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:2025.1
Vendors & Products Watchguard
Watchguard fireware Os
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Watchguard Fireware Os
cve-icon MITRE

Status: PUBLISHED

Assigner: WatchGuard

Published:

Updated: 2026-08-10T18:44:48.304Z

Reserved: 2026-06-29T14:21:49.222Z

Link: CVE-2026-13722

cve-icon Vulnrichment

Updated: 2026-07-06T14:56:56.796Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-03T00:16:52.010

Modified: 2026-08-10T19:17:28.810

Link: CVE-2026-13722

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-10T23:15:05Z

Weaknesses
  • CWE-347

    Improper Verification of Cryptographic Signature