Impact
A buffer overflow exists in the WatchGuard Fireware OS Management Web UI that only authenticated administrators can trigger by sending specially crafted network traffic. The flaw can lead to a denial of service or could allow arbitrary code execution on the device, giving the attacker full control of the affected system. The vulnerability is identified as CWE‑787 and represents a high‑risk flaw within the management interface.
Affected Systems
WatchGuard Fireware OS devices running versions earlier than Fireware OS 2026.2.2, Fireware OS 12.12.2, or Fireware OS 12.5.20 are impacted. These versions are used in Firebox appliances that provide network security services and are commonly deployed by organizations as their perimeter firewall. All devices that have not yet been upgraded to these patched releases remain vulnerable.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity and the lack of an EPSS score does not reduce the risk of exploitation. The flaw requires an attacker to have authenticated administrator access to the management interface, implying that it cannot be exploited by unauthenticated attackers. Once valid credentials are obtained – through compromise or default password usage – an attacker can send crafted packets to trigger the overflow, causing the device to crash or execute arbitrary code. The vulnerability is not listed in the CISA KEV catalog, but the potential for remote code execution warrants immediate attention.
OpenCVE Enrichment