Executive brief
A vulnerability in the management interface of WatchGuard Firebox security appliances could allow an administrator to crash the device's web-based management console. By sending specially crafted data to the system, the management interface may become unresponsive, hindering the ability to monitor or configure the firewall. This issue requires administrative credentials to exploit and primarily impacts the availability of the management tools rather than the firewall's core traffic-filtering capabilities.
Technical details
A denial-of-service vulnerability exists in the WatchGuard Fireware Management Web UI due to unsafe deserialization of untrusted data. An authenticated attacker with high privileges (administrator) can send crafted input to the 'put_data' endpoint to trigger the flaw. Successful exploitation causes the management web interface to become unavailable. The vulnerability is tracked as CWE-502 and affects multiple versions of Fireware OS, including the 12.x and 2025.x branches. Patches have been released in versions 12.12.1 and 2026.2.1, though some legacy models (T15/T35) remain unresolved.
Affected products
- WatchGuard Fireware OS 12.0 through 12.12, 12.5 through 12.5.18, 2025.1 through 2026.2
Timeline
- 2026-07-02: advisory: Initial advisory published by WatchGuard and NVD
- 2026-07-02: patched: Fixes released in versions 12.12.1 and 2026.2.1