Description
A vulnerability in WatchGuard Fireware OS may allow an attacker to bypass the Fireware OS filesystem integrity check and maintain limited persistence via a maliciously-crafted firmware update package.This issue affects Fireware OS 12.0 up to and including 12.11.7, 12.5.9 up to and including 12.5.16, and 2025.1 up to and including 2026.1.1.
Published: 2026-03-03
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Filesystem integrity bypass allowing limited persistence via malicious firmware update
Action: Patch
AI Analysis

Impact

A flaw in WatchGuard Fireware OS permits bypassing the operating system’s filesystem integrity verification, enabling an attacker to load a malicious firmware update package that retains limited persistence on the device. The weakness is a classic integrity bypass (CWE‑440) and compromises the assurance that firmware has not been altered, potentially allowing the attacker to modify critical system files or install additional malicious code. While the impact does not guarantee full remote code execution, the ability to persist on the system can be leveraged for long‑term reconnaissance or lateral movement within a network.

Affected Systems

The vulnerability affects WatchGuard Fireware OS versions 12.0 through 12.11.7, 12.5.9 through 12.5.16, and 2025.1 through 2026.1.1, which run on a wide range of Firebox hardware models including the M270, M290, M295, M370, M390, M395, M440, M4600, M470, M4800, M495, M5600, M570, M5800, M590, M595, M670, M690, M695, NV5, T115‑W, T125‑W, T125, T145‑W, T145, T15, T185, T20, T25, T35, T40, T45, T55, T70, T80, T85, Fireboxcloud, and Fireboxv devices.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate severity, but the EPSS score of less than 1% reflects a notably low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is the successful delivery and installation of a malicious firmware update, which requires either a compromised update source or an authenticated administrative channel. Once deployed, the attacker can achieve limited persistence and potentially gain further foothold on the network, making patching a priority.

Generated by OpenCVE AI on April 16, 2026 at 14:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest patched firmware version to all affected WatchGuard Fireware OS devices
  • Verify that applied firmware matches the official WatchGuard checksum or signature to ensure integrity
  • Restrict firmware update mechanisms to authenticated, signed sources and detect any unauthorized firmware changes
  • Monitor device logs for anomalous firmware update events and investigate promptly

Generated by OpenCVE AI on April 16, 2026 at 14:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 04 Mar 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Watchguard firebox M270
Watchguard firebox M290
Watchguard firebox M295
Watchguard firebox M370
Watchguard firebox M390
Watchguard firebox M395
Watchguard firebox M440
Watchguard firebox M4600
Watchguard firebox M470
Watchguard firebox M4800
Watchguard firebox M495
Watchguard firebox M5600
Watchguard firebox M570
Watchguard firebox M5800
Watchguard firebox M590
Watchguard firebox M595
Watchguard firebox M670
Watchguard firebox M690
Watchguard firebox M695
Watchguard firebox Nv5
Watchguard firebox T115-w
Watchguard firebox T125
Watchguard firebox T125-w
Watchguard firebox T145
Watchguard firebox T145-w
Watchguard firebox T15
Watchguard firebox T185
Watchguard firebox T20
Watchguard firebox T25
Watchguard firebox T35
Watchguard firebox T40
Watchguard firebox T45
Watchguard firebox T55
Watchguard firebox T70
Watchguard firebox T80
Watchguard firebox T85
Watchguard fireboxcloud
Watchguard fireboxv
Watchguard fireware
CPEs cpe:2.3:h:watchguard:firebox_m270:-:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_m290:-:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_m295:-:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_m370:-:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_m390:-:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_m395:-:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_m440:-:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_m4600:-:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_m470:-:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_m4800:-:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_m495:-:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_m5600:-:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_m570:-:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_m5800:-:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_m590:-:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_m595:-:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_m670:-:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_m690:-:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_m695:-:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_nv5:-:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_t115-w:-:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_t125-w:-:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_t125:-:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_t145-w:-:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_t145:-:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_t15:-:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_t185:-:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_t20:-:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_t25:-:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_t35:-:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_t40:-:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_t45:-:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_t55:-:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_t70:-:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_t80:-:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_t85:-:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:fireboxcloud:-:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:fireboxv:-:*:*:*:*:*:*:*
cpe:2.3:o:watchguard:fireware:*:*:*:*:*:*:*:*
Vendors & Products Watchguard firebox M270
Watchguard firebox M290
Watchguard firebox M295
Watchguard firebox M370
Watchguard firebox M390
Watchguard firebox M395
Watchguard firebox M440
Watchguard firebox M4600
Watchguard firebox M470
Watchguard firebox M4800
Watchguard firebox M495
Watchguard firebox M5600
Watchguard firebox M570
Watchguard firebox M5800
Watchguard firebox M590
Watchguard firebox M595
Watchguard firebox M670
Watchguard firebox M690
Watchguard firebox M695
Watchguard firebox Nv5
Watchguard firebox T115-w
Watchguard firebox T125
Watchguard firebox T125-w
Watchguard firebox T145
Watchguard firebox T145-w
Watchguard firebox T15
Watchguard firebox T185
Watchguard firebox T20
Watchguard firebox T25
Watchguard firebox T35
Watchguard firebox T40
Watchguard firebox T45
Watchguard firebox T55
Watchguard firebox T70
Watchguard firebox T80
Watchguard firebox T85
Watchguard fireboxcloud
Watchguard fireboxv
Watchguard fireware
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N'}


Wed, 04 Mar 2026 16:30:00 +0000

Type Values Removed Values Added
References

Wed, 04 Mar 2026 15:45:00 +0000

Type Values Removed Values Added
References

Tue, 03 Mar 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 03 Mar 2026 13:45:00 +0000

Type Values Removed Values Added
Description A vulnerability in WatchGuard Fireware OS may allow an attacker to bypass the Fireware OS filesystem integrity check and maintain limited persistence via a maliciously-crafted firmware update package.This issue affects Fireware OS 12.0 up to and including 12.11.7, 12.5.9 up to and including 12.5.16, and 2025.1 up to and including 2026.1.1.
Title WatchGuard Firebox System Integrity Check Bypass
First Time appeared Watchguard
Watchguard fireware Os
Weaknesses CWE-440
CPEs cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.0
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.5.9
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:2025.1
Vendors & Products Watchguard
Watchguard fireware Os
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Watchguard Firebox M270 Firebox M290 Firebox M295 Firebox M370 Firebox M390 Firebox M395 Firebox M440 Firebox M4600 Firebox M470 Firebox M4800 Firebox M495 Firebox M5600 Firebox M570 Firebox M5800 Firebox M590 Firebox M595 Firebox M670 Firebox M690 Firebox M695 Firebox Nv5 Firebox T115-w Firebox T125 Firebox T125-w Firebox T145 Firebox T145-w Firebox T15 Firebox T185 Firebox T20 Firebox T25 Firebox T35 Firebox T40 Firebox T45 Firebox T55 Firebox T70 Firebox T80 Firebox T85 Fireboxcloud Fireboxv Fireware Fireware Os
cve-icon MITRE

Status: PUBLISHED

Assigner: WatchGuard

Published:

Updated: 2026-03-04T15:22:41.878Z

Reserved: 2026-02-27T15:37:53.452Z

Link: CVE-2026-3344

cve-icon Vulnrichment

Updated: 2026-03-03T14:32:54.316Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-03T14:15:57.853

Modified: 2026-03-04T19:19:41.717

Link: CVE-2026-3344

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-16T14:15:28Z

Weaknesses