Impact
The WatchGuard Agent suffers an improper authentication flaw. An attacker that can reach the agent over the network, without needing prior credentials, can trigger the agent to run arbitrary code with elevated privileges. The flaw enables full control over the host, allowing data theft, lateral movement, and additional exploitation. The weakness corresponds to CWE-306, CWE-347, and CWE-494.
Affected Systems
All installations of WatchGuard Agent before the vendor‑released patches (1.17.02.0000, 1.17.21.0000, 1.25.13.0000) are affected. The vulnerability applies to the agent component that listens for remote management commands; any deployment with network exposure to untrusted hosts without authentication is at risk.
Risk and Exploitability
The CVSS base score of 9.3 marks the issue as critical. Although no EPSS value is available, the absence of an EPSS figure suggests either limited data or low exploitation probability, but the implication remains severe. Since it is not listed in the CISA KEV catalog, the risk relies on the attacker’s ability to reach the agent. With network access and no authentication required, the attack vector is straightforward, making the vulnerability a high‑priority target for threat actors.
OpenCVE Enrichment