Impact
The WatchGuard Agent contains a path traversal flaw that enables an unauthenticated attacker on a nearby network to execute arbitrary code on the target machine. This flaw allows the attacker to bypass authorization checks and manipulate file paths, meeting the criteria of CWE-306 and CWE-94, and ultimately achieve full system compromise, affecting confidentiality, integrity, and availability.
Affected Systems
The vulnerability affects all versions of WatchGuard Agent prior to 1.25.13.0000. Devices running the older, unpatched WatchGuard Agent software are susceptible to exploitation.
Risk and Exploitability
The CVSS base score of 9.4 indicates a critical risk, while an absent EPSS score does not imply low exploitation probability but suggests no recent known exploits. Because the flaw allows unauthenticated remote exploitation, an attacker with network visibility could launch the payload without further credentials. Once exploited, the attacker can execute arbitrary commands with system privileges, thereby creating a persistent foothold. The lack of a KEV listing indicates that there are currently no confirmed widespread attacks, but the high severity justifies immediate action.
OpenCVE Enrichment