Description
In exception circumstances, WatchGuard Fireware OS on a FireCluster may use a hard-coded encryption key to encrypt saved credentials for Access Portal resources.

This vulnerability affects Fireware OS 12.1 up to and including 12.12 and 2025.1 up to and including 2026.2. This vulnerability does not affect devices that do not support the Access Portal feature or standalone Fireboxes not deployed in a FireCluster.
Published: 2026-07-02
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A hard‑coded encryption key is used to encrypt saved credentials for Access Portal resources in certain exception circumstances on WatchGuard Fireware OS running in a FireCluster. This weakness (CWE‑798) allows an attacker who can read the credential database to decrypt usernames and passwords, compromising authenticated sessions and eliminating confidentiality of stored credentials.

Affected Systems

WatchGuard Fireware OS versions 12.1 through 12.12 and 2025.1 through 2026.2 that operate within a enabled. Devices that do not support Access Portal or are standalone Fireboxes are not impacted.

Risk and Exploitability

The CVSS score of 5.9 indicates a moderate risk. An EPSS score of less than 1%. Because the vulnerability only exposes encryption weakness, an attacker must first obtain read access to the credential database, requiring prior compromise not listed in the CISA KEV catalog. No public exploitation has been reported, but credential compromise would be possible if the database is accessed.

Generated by OpenCVE AI on July 22, 2026 at 13:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade WatchGuard Fireware OS to the latest release that removes the hard‑coded fallback encryption key, as indicated in the vendor advisory.
  • If an upgrade is not immediately possible, restrict access to the Access Portal credential database by enforcing strict physical and network controls and disable the Access Portal feature on Fireboxes that do not use a FireCluster.
  • Monitor system logs for unauthorized reads of the credential database and audit Access Portal configuration to ensure the service is only enabled on required devices.

Generated by OpenCVE AI on July 22, 2026 at 13:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Description In exception circumstances, WatchGuard Fireware OS on a FireCluster may use a hard-coded encryption key to encrypt saved credentials for Access Portal resources. This vulnerability affects Fireware OS 12.1 up to and including 12.12 and 2025.1 up to and including 2026.2. This vulnerability does not affect devices that do not support the Access Portal feature or standalone Fireboxes not deployed in a FireCluster.
Title WatchGuard Firebox Hardcoded Fallback Encryption Key in Access Portal Resource Credential Database
First Time appeared Watchguard
Watchguard fireware Os
Weaknesses CWE-798
CPEs cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.1
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:2025.1
Vendors & Products Watchguard
Watchguard fireware Os
References
Metrics cvssV4_0

{'score': 5.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N'}


Subscriptions

Watchguard Fireware Os
cve-icon MITRE

Status: PUBLISHED

Assigner: WatchGuard

Published:

Updated: 2026-07-06T14:56:01.465Z

Reserved: 2026-06-29T14:36:27.889Z

Link: CVE-2026-13728

cve-icon Vulnrichment

Updated: 2026-07-06T14:55:57.806Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-22T13:30:05Z

Weaknesses
  • CWE-798

    Use of Hard-coded Credentials