Executive brief
A security vulnerability exists in the management interface of WatchGuard Firebox firewalls, which are used to protect corporate networks. An authorized administrator could exploit this flaw to take full control of the device and execute unauthorized commands. This could lead to a complete compromise of the firewall, potentially allowing an attacker to intercept network traffic or disable security protections.
Technical details
An out-of-bounds (OOB) write vulnerability (CWE-787) exists within the 'wgagent' process of WatchGuard Fireware OS. The flaw is reachable via the Management Web UI. An attacker with high privileges (authenticated) can send specially crafted requests to trigger the memory corruption, leading to arbitrary code execution on the underlying operating system. The vulnerability affects multiple versions across the 12.x and 2025.x branches. Patches have been released in versions 12.12.1 and 2026.2.1, though some legacy models (T15/T35) remain unresolved according to the advisory.
Affected products
- WatchGuard Fireware OS 12.1 through 12.12, 12.5 through 12.5.18, 2025.1 through 2026.2
Timeline
- 2026-07-02: advisory: WatchGuard published advisory WGSA-2026-00021
- 2026-07-02: patched: Fixes released in versions 12.12.1 and 2026.2.1
- 2026-07-03: disclosed: NVD publication date