Impact
A NULL pointer dereference flaw in the authentication process of WatchGuard Fireware OS allows an unauthenticated remote attacker to crash the management daemon by sending a specially crafted request to the login interface. This causes a denial of service that interrupts remote management sessions. The underlying weakness is a null pointer dereference (CWE‑476), which leads the software to attempt to access uninitialized memory and crash.
Affected Systems
The vulnerability affects WatchGuard Fireware OS devices running any of the following versions: 2026.3.2, 2026.2.3, 12.12.3, and 12.5.21. Devices running earlier releases that have not applied the listed updates are vulnerable.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity impact on availability, while the EPSS score is not available and the flaw is not listed in the CISA KEV catalog. The likely attack path involves an unauthenticated remote attacker sending a crafted packet to the management daemon’s login endpoint; no authentication is required, and the exploit can be performed from any network that can reach the device. If successful, the daemon will crash, causing a temporary loss of remote management functionality until a restart occurs.
OpenCVE Enrichment