Description
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow an unauthenticated attacker on the same local network segment to execute arbitrary code.




This vulnerability affects Fireware OS 11.0 up to and including 11.12.4_Update1, 12.0 up to and including 12.12 and 2025.1 up to and including 2026.2.
Published: 2026-07-02
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is an out‑of‑bounds write in the admd service of WatchGuard Fireware OS, a classic buffer overflow (CWE-120). An attacker who can reach the service from the same local network segment without authentication may send a crafted packet that triggers the overflow, allowing arbitrary code execution on the device. The CVE description states that an unauthenticated attacker on the same local network segment can exploit this weakness.

Affected Systems

WatchGuard Fireware OS versions 11.0 through 11.12.4_Update1, 12.0 through 12.12, and 2025.1 through 2026.2 are affected. The vulnerability is present in the admd component across these releases.

Risk and Exploitability

The CVSS score of 7.7 indicates high severity, while the EPSS score of < 1 % and absence from the CISA KEV catalog suggest a low likelihood of exploitation at this time. The attack requires local network access to the admd service and no authentication. Once exploited, the flaw can lead to arbitrary code execution, giving an attacker full control over the affected device.

Generated by OpenCVE AI on July 21, 2026 at 10:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest patch or upgrade to a patched release of WatchGuard Fireware OS that resolves the out‑of‑bounds write flaw.
  • If an upgrade is not immediately possible, block or limit traffic to the admd port from non‑management network segments using firewall rules to prevent local‑segment reachability.
  • If the admd service must remain reachable, isolate it onto a dedicated management VLAN, enforce strict authentication, and restrict access to authorized management users only.
  • Enable detailed logging for the admd service to detect anomalous activity or payloads.

Generated by OpenCVE AI on July 21, 2026 at 10:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Description An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow an unauthenticated attacker on the same local network segment to execute arbitrary code. This vulnerability affects Fireware OS 11.0 up to and including 11.12.4_Update1, 12.0 up to and including 12.12 and 2025.1 up to and including 2026.2.
Title WatchGuard Firebox admd Out of Bounds Write Vulnerability
First Time appeared Watchguard
Watchguard fireware Os
Weaknesses CWE-120
CPEs cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:11.0
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.0
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.5
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:2025.1
Vendors & Products Watchguard
Watchguard fireware Os
References
Metrics cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Watchguard Fireware Os
cve-icon MITRE

Status: PUBLISHED

Assigner: WatchGuard

Published:

Updated: 2026-07-07T03:56:33.916Z

Reserved: 2026-05-10T12:48:43.918Z

Link: CVE-2026-8247

cve-icon Vulnrichment

Updated: 2026-07-06T15:46:54.782Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T10:45:02Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')