Impact
WatchGuard Fireware OS contains a firmware validation bypass when processing a backup image via the backup/restore feature. An authenticated administrator who uploads a tampered firmware image will be accepted because the integrity check is circumvented, allowing the installation of arbitrary firmware. This can lead to full device compromise with malicious code executed on the appliance.
Affected Systems
WatchGuard Fireware OS is affected. Devices running any firmware version that has not yet incorporated the security update delivered in Fireware OS 2026.2.1 or Fireware OS 12.12.1 are vulnerable. The backup/restore feature is the entry point, so any appliance that supports this functionality and runs an earlier release is at risk.
Risk and Exploitability
The CVSS score of 8.6 marks this vulnerability as high severity, while the EPSS score of less than 1% indicates a low current likelihood of exploitation. Because the attack requires authenticated administrator credentials, an attacker would need to compromise or spoof those credentials before uploading a malicious firmware image via the backup/restore interface. The vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known exploits yet.
OpenCVE Enrichment