Executive brief
WatchGuard Fireware OS is the operating system that powers WatchGuard Firebox network firewalls, which protect corporate networks and data. A vulnerability allows an attacker to bypass filesystem integrity checks by crafting a malicious firmware update package, potentially maintaining limited persistence on the device and evading detection of unauthorized modifications.
Technical details
This vulnerability in WatchGuard Fireware OS (CWE-440: Expected Behavior Violation) allows an attacker to bypass the filesystem integrity check mechanism by submitting a maliciously-crafted firmware update package. The flaw is classified as a software integrity attack (CAPEC-184). An attacker with the ability to upload a malicious firmware package can achieve limited persistence on the affected Fireware OS device while circumventing the integrity verification controls. Patches are available: Fireware OS 2026.1.2, Fireware OS 12.11.8 for the default platform, and Fireware OS 12.5.17 for T15/T35 models.
Affected products
- WatchGuard Fireware OS Default platform >= 2025.1, < 2026.1.2; >= 12.0, < 12.11.8; T15/T35 >= 12.0, < 12.5.17
Timeline
- 2026-03-03: disclosed
- 2026-03-03: patched: Patches released: Fireware OS 2026.1.2, 12.11.8 (default), 12.5.17 (T15/T35)