Description
In exception circumstances, WatchGuard Fireware OS on a FireCluster may use a hard-coded encryption key to encrypt saved credentials for Access Portal resources.

This vulnerability does not affect devices that do not support the Access Portal feature or standalone Fireboxes not deployed in a FireCluster.
Published: 2026-07-02
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

In certain exceptional circumstances, devices running WatchGuard Fireware OS as part of a FireCluster use a hard-coded fallback encryption key to encrypt stored credentials for Access Portal resources. This weakness (CWE-798) permits an attacker who can read the credential database to recover usernames and passwords, compromising authenticated sessions and undermining credential confidentiality. The flaw is limited to FireCluster deployments with the Access Portal feature enabled; devices that do not support Access Portal or are standalone Fireboxes not in a FireCluster are not affected.

Affected Systems

WatchGuard Fireware OS devices that are part of a FireCluster and have the Access Portal feature enabled are affected. Devices that do not support the Access Portal feature or standalone Fireboxes not deployed in a FireCluster are not impacted.

Risk and Exploitability

The CVSS score of 5.9 indicates a moderate risk, while an EPSS score of less than 1% suggests a very low probability of exploitation. Because the flaw only weakens the encryption of the credential database, an attacker must first obtain read access to that database, implying a prerequisite compromise. The vulnerability is not listed in CISA KEV and no public exploitation has been reported. Were the database accessed, credential compromise would be possible.

Generated by OpenCVE AI on August 10, 2026 at 23:09 UTC.

Remediation

Vendor Solution

Fireware OS 2026.2.1, Fireware OS 12.12.1


OpenCVE Recommended Actions

  • Upgrade WatchGuard Fireware OS to the latest release that removes the hard-coded fallback encryption key, as specified in the vendor advisory.
  • If an upgrade is not immediately possible, restrict access to the Access Portal credential database by enforcing strict physical and network controls and, when feasible, disable the Access Portal feature on Fireboxes that do not use a FireCluster.
  • Monitor system logs for unauthorized reads of the credential database and audit Access Portal configuration to ensure the service is only enabled on required devices.

Generated by OpenCVE AI on August 10, 2026 at 23:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 10 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description In exception circumstances, WatchGuard Fireware OS on a FireCluster may use a hard-coded encryption key to encrypt saved credentials for Access Portal resources. This vulnerability affects Fireware OS 12.1 up to and including 12.12 and 2025.1 up to and including 2026.2. This vulnerability does not affect devices that do not support the Access Portal feature or standalone Fireboxes not deployed in a FireCluster. In exception circumstances, WatchGuard Fireware OS on a FireCluster may use a hard-coded encryption key to encrypt saved credentials for Access Portal resources. This vulnerability does not affect devices that do not support the Access Portal feature or standalone Fireboxes not deployed in a FireCluster.
CPEs cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.1
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:2025.1
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:*
References

Mon, 06 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Description In exception circumstances, WatchGuard Fireware OS on a FireCluster may use a hard-coded encryption key to encrypt saved credentials for Access Portal resources. This vulnerability affects Fireware OS 12.1 up to and including 12.12 and 2025.1 up to and including 2026.2. This vulnerability does not affect devices that do not support the Access Portal feature or standalone Fireboxes not deployed in a FireCluster.
Title WatchGuard Firebox Hardcoded Fallback Encryption Key in Access Portal Resource Credential Database
First Time appeared Watchguard
Watchguard fireware Os
Weaknesses CWE-798
CPEs cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.1
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:2025.1
Vendors & Products Watchguard
Watchguard fireware Os
References
Metrics cvssV4_0

{'score': 5.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N'}


Subscriptions

Watchguard Firebox M270 Firebox M290 Firebox M295 Firebox M370 Firebox M390 Firebox M395 Firebox M440 Firebox M4600 Firebox M470 Firebox M4800 Firebox M495 Firebox M5600 Firebox M570 Firebox M5800 Firebox M590 Firebox M595 Firebox M670 Firebox M690 Firebox M695 Firebox Nv5 Firebox T115-w Firebox T125 Firebox T125-w Firebox T145 Firebox T145-w Firebox T185 Firebox T20 Firebox T25 Firebox T40 Firebox T45 Firebox T55 Firebox T70 Firebox T80 Firebox T85 Fireboxcloud Fireboxv Fireware Fireware Os
cve-icon MITRE

Status: PUBLISHED

Assigner: WatchGuard

Published:

Updated: 2026-08-10T19:08:31.803Z

Reserved: 2026-06-29T14:36:27.889Z

Link: CVE-2026-13728

cve-icon Vulnrichment

Updated: 2026-07-06T14:55:57.806Z

cve-icon NVD

Status : Modified

Published: 2026-07-03T00:16:52.147

Modified: 2026-08-10T20:17:26.390

Link: CVE-2026-13728

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-10T23:15:05Z

Weaknesses
  • CWE-798

    Use of Hard-coded Credentials