Impact
WatchGuard Fireware OS has a firmware validation bypass that occurs when a backup image is processed through the backup/restore feature. An authenticated administrator can upload a tampered firmware image that the system accepts, bypassing integrity checks. This flaw allows the attacker to install unauthorized firmware, potentially giving full device compromise by enabling arbitrary code execution or persistent footholds.
Affected Systems
Devices running WatchGuard Fireware OS 11.0 through 11.12.4_Update1, 12.0 through 12.12, or 2025.1 through 2025.6.2 are affected. The vulnerability is triggered by restore functionality, so any appliance using this feature with any of the listed firmware versions is at risk.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity, while the EPSS score of less than 1% suggests exploitation probability is currently low and the vulnerability is not listed in the CISA KEV catalog. The only attack vector is an authenticated administrator, implying an internal threat. If an attacker gains administrative credentials or succeeds in social engineering, they can upload a malicious firmware image via the backup/restore interface, install it, and thereby achieve full control of the device.
OpenCVE Enrichment