Executive brief
WatchGuard Fireware OS is used in firewalls and security appliances to manage network access and authentication. An LDAP injection vulnerability in the authentication and management web interfaces allows unauthenticated attackers to extract sensitive information from connected LDAP servers and potentially authenticate as other users if they possess valid credentials, bypassing normal security controls.
Technical details
The vulnerability is an LDAP injection flaw (CWE-90) in WatchGuard Fireware OS that affects the authentication and management web interfaces. An unauthenticated remote attacker can craft malicious LDAP queries to retrieve sensitive information from connected LDAP authentication servers. Additionally, if an attacker has a valid user's passphrase, they can authenticate as that LDAP user using a partial identifier by exploiting the improper neutralization of special LDAP characters. The attack vector is network-based with no authentication required. Patches are available: Fireware OS 2026.1 and later, Fireware OS 12.11.7 and later, and Fireware OS 12.5.16 and later.
Affected products
- WatchGuard Fireware OS 2025.1 to 2026.0, 12.0 to 12.11.6
Timeline
- 2026-01-30: disclosed
- 2026-08-24: patched: Patches released for Fireware OS 2026.1, 12.11.7, and 12.5.16