Impact
A hard‑coded encryption key is used to encrypt saved credentials for Access Portal resources in certain exception circumstances on WatchGuard Fireware OS running in a FireCluster. This weakness (CWE‑798) allows an attacker who can read the credential database to decrypt usernames and passwords, compromising authenticated sessions and eliminating confidentiality of stored credentials.
Affected Systems
WatchGuard Fireware OS versions 12.1 through 12.12 and 2025.1 through 2026.2 that operate within a enabled. Devices that do not support Access Portal or are standalone Fireboxes are not impacted.
Risk and Exploitability
The CVSS score of 5.9 indicates a moderate risk. An EPSS score of less than 1%. Because the vulnerability only exposes encryption weakness, an attacker must first obtain read access to the credential database, requiring prior compromise not listed in the CISA KEV catalog. No public exploitation has been reported, but credential compromise would be possible if the database is accessed.
OpenCVE Enrichment