Impact
A Cross‑Site Request Forgery flaw, identified as CWE-352, exists in the Fireware OS WebUI. A remote attacker can get an authenticated administrator to load a crafted malicious page, which can cause the WebUI to crash or become unavailable, effectively denying administrative access. The vulnerability does not grant code execution or system compromise; its impact is limited to service disruption.
Affected Systems
All WatchGuard Fireware OS appliances that run the Fireware OS WebUI and have not been updated to the fixed releases—Fireware OS 2026.2, 12.12, or 12.5.18—are potentially affected. Any Firebox device provisioned with these firmware versions is at risk.
Risk and Exploitability
The CVSS base score of 7.1 classifies the vulnerability as moderate to high. The EPSS score of 0.00223 indicates a very low expected exploitation probability. The flaw is not included in the CISA KEV catalog, suggesting no known large‑scale exploitation. Exploitation requires an attacker to entice an authenticated administrator to visit a malicious URL; no privilege escalation or remote code execution is needed, but the resulting denial can impair administrative operations.
OpenCVE Enrichment