Executive brief
A security vulnerability has been identified in WatchGuard Fireware OS, the operating system used by Firebox network security appliances. An attacker located on the same local network could exploit this flaw to take control of the device and execute unauthorized commands. This could lead to a total compromise of the firewall, potentially allowing attackers to intercept traffic or gain further access to the internal corporate network.
Technical details
An out-of-bounds write vulnerability (CWE-120) exists in the 'admd' component of WatchGuard Fireware OS. The flaw is caused by a buffer copy without checking the size of the input, leading to memory corruption. An unauthenticated attacker on the same local network segment (Adjacent vector) can exploit this to achieve arbitrary code execution with high privileges. The vulnerability affects multiple major versions of Fireware OS, including the 11.x, 12.x, and 2025.x branches. Patches are available for most versions (e.g., 12.12.1, 2026.2.1), though some legacy 11.x versions are listed as End of Life.
Affected products
- WatchGuard Fireware OS 11.0 to 11.12.4_Update1, 12.0 to 12.12, 12.5 to 12.5.18, 2025.1 to 2026.2
Timeline
- 2026-07-02: advisory: Initial advisory published by WatchGuard and NVD
- 2026-07-02: patched: Fixed versions 2026.2.1 and 12.12.1 released