Description
WatchGuard Fireware OS contains a firmware validation bypass when processing a backup image via the backup/restore feature. An authenticated administrator can exploit this vulnerability to install a tampered firmware image.This vulnerability affects Fireware OS 11.0 up to and including 11.12.4_Update1, 12.0 up to and including 12.12 and 2025.1 up to and including 2025.6.2.
Published: 2026-07-02
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

WatchGuard Fireware OS has a firmware validation bypass that occurs when a backup image is processed through the backup/restore feature. An authenticated administrator can upload a tampered firmware image that the system accepts, bypassing integrity checks. This flaw allows the attacker to install unauthorized firmware, potentially giving full device compromise by enabling arbitrary code execution or persistent footholds.

Affected Systems

Devices running WatchGuard Fireware OS 11.0 through 11.12.4_Update1, 12.0 through 12.12, or 2025.1 through 2025.6.2 are affected. The vulnerability is triggered by restore functionality, so any appliance using this feature with any of the listed firmware versions is at risk.

Risk and Exploitability

The CVSS score of 8.6 indicates high severity, while the EPSS score of less than 1% suggests exploitation probability is currently low and the vulnerability is not listed in the CISA KEV catalog. The only attack vector is an authenticated administrator, implying an internal threat. If an attacker gains administrative credentials or succeeds in social engineering, they can upload a malicious firmware image via the backup/restore interface, install it, and thereby achieve full control of the device.

Generated by OpenCVE AI on July 21, 2026 at 10:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor-supplied firmware update that fixes the validation bypass to all affected devices.
  • If an update cannot be applied immediately, disable the backup/restore feature or restrict it to trusted administrators only.
  • Enforce strong authentication, least privilege, and monitor firmware upload logs for unauthorized activity.

Generated by OpenCVE AI on July 21, 2026 at 10:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Description WatchGuard Fireware OS contains a firmware validation bypass when processing a backup image via the backup/restore feature. An authenticated administrator can exploit this vulnerability to install a tampered firmware image.This vulnerability affects Fireware OS 11.0 up to and including 11.12.4_Update1, 12.0 up to and including 12.12 and 2025.1 up to and including 2025.6.2.
Title WatchGuard Firebox Firmware Image Validation Bypass in WatchGuard Fireware OS
First Time appeared Watchguard
Watchguard fireware Os
Weaknesses CWE-347
CPEs cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:11.0
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.0
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.5
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:2025.1
Vendors & Products Watchguard
Watchguard fireware Os
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Watchguard Fireware Os
cve-icon MITRE

Status: PUBLISHED

Assigner: WatchGuard

Published:

Updated: 2026-07-07T03:56:36.130Z

Reserved: 2026-06-29T14:21:49.222Z

Link: CVE-2026-13722

cve-icon Vulnrichment

Updated: 2026-07-06T14:56:56.796Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T10:45:02Z

Weaknesses
  • CWE-347

    Improper Verification of Cryptographic Signature