Impact
The vulnerability is insecure deserialization in Fireware Access Portal. An attacker who has achieved write access to the local filesystem can craft a malicious payload that is deserialized by the portal, enabling arbitrary code execution under the portald user. This can lead to full control over the device, compromising confidentiality, integrity, and availability.
Affected Systems
The vulnerability affects WatchGuard Fireware OS on devices that support the Access Portal feature. No specific version ranges are indicated in the CNA data. Firebox models that do not implement Access Portal, such as the Tâ15 and Tâ35, are not impacted.
Risk and Exploitability
The CVSS score of 8.4 indicates a high severity level. The EPSS score of less than 1% points to a low but nonzero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an initial foothold that provides local write privileges; once that condition is met, an attacker can trigger insecure deserialization to execute code. Consequently, systems that have not applied a patch or mitigated the prerequisite vulnerability face a high risk of compromise.
OpenCVE Enrichment