Impact
The flaw is an out‑of‑bounds write in the admd service of WatchGuard Fireware OS, a classic buffer overflow (CWE-120). An attacker who can reach the service from the same local network segment without authentication may send a crafted packet that triggers the overflow, allowing arbitrary code execution on the device. The CVE description states that an unauthenticated attacker on the same local network segment can exploit this weakness.
Affected Systems
WatchGuard Fireware OS versions 11.0 through 11.12.4_Update1, 12.0 through 12.12, and 2025.1 through 2026.2 are affected. The vulnerability is present in the admd component across these releases.
Risk and Exploitability
The CVSS score of 7.7 indicates high severity, while the EPSS score of < 1 % and absence from the CISA KEV catalog suggest a low likelihood of exploitation at this time. The attack requires local network access to the admd service and no authentication. Once exploited, the flaw can lead to arbitrary code execution, giving an attacker full control over the affected device.
OpenCVE Enrichment