Executive brief
A security vulnerability exists in the management interface of WatchGuard Firebox firewalls, which are used to secure corporate networks. An attacker with administrative access could bypass security restrictions to write unauthorized files to the device's internal storage. This could lead to a complete takeover of the firewall, potentially allowing the attacker to disrupt network traffic or gain further access to the internal network.
Technical details
A path traversal vulnerability (CWE-22) exists in the Management Web UI of WatchGuard Fireware OS. The flaw is caused by improper validation of user-supplied paths, allowing an authenticated attacker with high privileges to escape the intended directory and write arbitrary files to the Firebox filesystem. The attack is reachable over the network via the management interface. Successful exploitation could lead to full system compromise or persistent unauthorized access. Patches are available in versions 12.12.1 and 2026.2.1, though some older versions (11.x and 12.5.x) remain unresolved or are end-of-life.
Affected products
- WatchGuard Fireware OS 11.0 to 11.12.4_Update1, 12.0 to 12.12, 12.5 to 12.5.18, 2025.1 to 2026.2
Timeline
- 2026-07-02: advisory: WatchGuard published advisory WGSA-2026-00028
- 2026-07-02: patched: Resolved versions 12.12.1 and 2026.2.1 released