cbcvebase.

Watchguard Fireware Os vulnerabilities

69 known vulnerabilities affecting watchguard/fireware_os.

Total CVEs
69
CISA KEV
2
actively exploited
Public exploits
1
Exploited in wild
2
Severity breakdown
CRITICAL7HIGH41MEDIUM21

Vulnerabilities

Page 2 of 4
CVE-2025-1545P3HIGHCVSS 7.5≥ 2025.1, < 2025.1.3≥ 12.0, < 12.11.5+2 more2025-12-04
CVE-2025-1545 [HIGH] CWE-91 CVE-2025-1545: An XPath Injection vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attack An XPath Injection vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to retrieve sensitive information from the Firebox configuration through an exposed authentication or management web interface. This vulnerability only affects Firebox systems that have at least one authentication hotspot configured.
nvd
CVE-2026-3342P3HIGHCVSS 7.2≥ 11.9, ≤ 11.12.4+541730≥ 12.0, ≤ 12.11.7+2 more2026-03-03
CVE-2026-3342 [HIGH] CWE-787 CVE-2026-3342: An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow an authenticated privileged An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow an authenticated privileged administrator to execute arbitrary code with root permissions via an exposed management interface. This vulnerability affects Fireware OS 11.9 up to and including 11.12.4_Update1, 12.0 up to and including 12.11.7 and 2025.1 up to and including 2026.1.1.
nvd
CVE-2026-3987P3HIGHCVSS 7.2≥ 2025.1, < 2026.2≥ 12.6.1, < 12.122026-04-01
CVE-2026-3987 [HIGH] CWE-22 CVE-2026-3987: A path traversal vulnerability in the Fireware OS Web UI on WatchGuard Firebox systems may allow a p A path traversal vulnerability in the Fireware OS Web UI on WatchGuard Firebox systems may allow a privileged authenticated remote attacker to execute arbitrary code in the context of an elevated system process.
nvd
CVE-2026-13054P3HIGHCVSS 7.2≥ 2025.1, < 2026.2.1≥ 12.0, < 12.12.1+3 more2026-07-03
CVE-2026-13054 [HIGH] CWE-22 CVE-2026-13054: A path traversal vulnerability in the WatchGuard Fireware OS Management Web UI allows a privileged a A path traversal vulnerability in the WatchGuard Fireware OS Management Web UI allows a privileged authenticated attacker to write arbitrary files on the Firebox's filesystem.
nvd
CVE-2025-1547P3HIGHCVSS 7.2≥ 12.0, ≤ 12.11.3≥ 12.0, < 12.5.132025-12-04
CVE-2025-1547 [HIGH] CWE-121 CVE-2025-1547: A stack-based buffer overflow vulnerability [CWE-121] in WatchGuard Fireware OS's certificate reques A stack-based buffer overflow vulnerability [CWE-121] in WatchGuard Fireware OS's certificate request command could allow an authenticated privileged user to execute arbitrary code via specially crafted CLI commands.
nvd
CVE-2025-4106P3HIGHCVSS 8.9≥ 12.0, < 12.11.3≥ 12.0, < 12.5.132025-10-24
CVE-2025-4106 [HIGH] CWE-489 CVE-2025-4106: An authenticated admin user with access to both the management WebUI and command line interface on a An authenticated admin user with access to both the management WebUI and command line interface on a Firebox can enable a diagnostic debug shell by uploading a platform and version-specific diagnostic package and executing a leftover diagnostic command.
nvd
CVE-2026-13084P3HIGHCVSS 7.5≥ 2025.1, < 2026.2.1≥ 12.0, < 12.12.1+3 more2026-07-03
CVE-2026-13084 [HIGH] CWE-476 CVE-2026-13084: A null pointer dereference vulnerability in WatchGuard Fireware OS may allow a remote unauthenticate A null pointer dereference vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to create a denial-of-service (DoS) condition by sending specially crafted IKEv2 messages. This vulnerability affects both the Mobile User VPN with IKEv2 and the Branch Office VPN using IKEv2 when configured with a dynamic gateway peer. This
nvd
CVE-2026-86132P3HIGHCVSS 7.5≥ 2026.3, < 2026.3.2≥ 2025.0, < 2026.2.3+2 more2026-09-30
CVE-2026-86132 [HIGH] CWE-191 CVE-2026-86132: An integer underflow vulnerability in the WatchGuard Fireware OS IKEv2 daemon (iked) allows a remote An integer underflow vulnerability in the WatchGuard Fireware OS IKEv2 daemon (iked) allows a remote, unauthenticated attacker to crash the process by sending a specially crafted encrypted IKEv2 message negotiated with an AES-GCM cipher suite.
nvd
CVE-2025-12195P3HIGHCVSS 7.2≥ 2025.1, < 2025.1.3≥ 12.0, < 12.11.5+2 more2025-12-04
CVE-2025-12195 [HIGH] CWE-787 CVE-2025-12195: An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated pr An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to execute arbitrary code via specially crafted IPSec configuration CLI commands.
nvd
CVE-2026-13053P3HIGHCVSS 7.2≥ 2025.1, < 2026.2.1≥ 12.0, < 12.12.1+3 more2026-07-03
CVE-2026-13053 [HIGH] CWE-787 CVE-2026-13053: An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated pr An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to execute arbitrary code via a specially crafted CLI command.
nvd
CVE-2025-12196P3HIGHCVSS 7.2v2025.1≥ 12.0, < 12.11.5+1 more2025-12-04
CVE-2025-12196 [HIGH] CWE-787 CVE-2025-12196: An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated pr An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to execute arbitrary code via a specially crafted CLI command.
nvd
CVE-2025-12026P3HIGHCVSS 7.2≥ 2025.1, < 2025.1.3≥ 12.0, ≤ 12.11.5+1 more2025-12-04
CVE-2025-12026 [HIGH] CWE-787 CVE-2025-12026: An Out-of-bounds Write vulnerability in WatchGuard Fireware OS’s certificate request command could a An Out-of-bounds Write vulnerability in WatchGuard Fireware OS’s certificate request command could allow an authenticated privileged user to execute arbitrary code via specially crafted CLI commands.
nvd
CVE-2026-13224P3HIGHCVSS 8.2≥ 12.0, < 12.5.21≥ 2026.3, < 2026.3.2+2 more2026-09-30
CVE-2026-13224 [HIGH] CWE-22 CVE-2026-13224: A path traversal vulnerability in the Fireware OS WebUI management agent allows an authenticated adm A path traversal vulnerability in the Fireware OS WebUI management agent allows an authenticated administrator to read or list arbitrary files on the local filesystem by sending a specially crafted management request.
nvd
CVE-2026-86104P3HIGHCVSS 7.5≥ 2026.3, < 2026.3.2≥ 2025.0, < 2026.2.3+2 more2026-09-30
CVE-2026-86104 [HIGH] CWE-400 CVE-2026-86104: An uncontrolled resource consumption vulnerability in the Fireware OS login process (wgagent) allows An uncontrolled resource consumption vulnerability in the Fireware OS login process (wgagent) allows a remote, unauthenticated attacker to cause a denial of service by sending a specially crafted request.
nvd
CVE-2026-13383P3HIGHCVSS 7.2≥ 2025.1, < 2026.2.1≥ 12.1, < 12.12.1+2 more2026-07-03
CVE-2026-13383 [HIGH] CWE-787 CVE-2026-13383: An Out-of-bounds Write vulnerability in WatchGuard Fireware OS ikestubd process could allow an authe An Out-of-bounds Write vulnerability in WatchGuard Fireware OS ikestubd process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the Management Web UI.
nvd
CVE-2026-13384P3HIGHCVSS 7.2≥ 2025.1, < 2026.2.1≥ 12.1, < 12.12.1+2 more2026-07-03
CVE-2026-13384 [HIGH] CWE-787 CVE-2026-13384: An Out-of-bounds Write vulnerability in WatchGuard Fireware OS wgagent process could allow an authen An Out-of-bounds Write vulnerability in WatchGuard Fireware OS wgagent process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the Management Web UI.
nvd
CVE-2026-13050P3HIGHCVSS 7.2≥ 2025.1, < 2026.2.1≥ 12.0, < 12.12.1+3 more2026-07-03
CVE-2026-13050 [HIGH] CWE-787 CVE-2026-13050: An Out-of-bounds Write vulnerability in WatchGuard Fireware OS networkd process could allow an authe An Out-of-bounds Write vulnerability in WatchGuard Fireware OS networkd process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the Management Web UI.
nvd
CVE-2026-86101P3HIGHCVSS 7.2≥ 2026.3, < 2026.3.2≥ 2025.0, < 2026.2.3+2 more2026-09-30
CVE-2026-86101 [HIGH] CWE-285 CVE-2026-86101: An improper authorization vulnerability in WatchGuard Fireware OS's SAML login process allows a remo An improper authorization vulnerability in WatchGuard Fireware OS's SAML login process allows a remote, authenticated SAML user with access only to the Access Portal to obtain unauthorized Mobile VPN with SSL access through a specially crafted request.
nvd
CVE-2026-86134P3HIGHCVSS 7.5≥ 2026.3, < 2026.3.2≥ 2025.0, < 2026.2.3+2 more2026-09-30
CVE-2026-86134 [HIGH] CWE-476 CVE-2026-86134: A NULL pointer dereference vulnerability in the WatchGuard Fireware OS authentication process allows A NULL pointer dereference vulnerability in the WatchGuard Fireware OS authentication process allows a remote, unauthenticated attacker to crash the management daemon by sending a specially request to the login interface, resulting in a denial of service.
nvd
CVE-2026-13046P3HIGHCVSS 7.5≥ 2026.3, < 2026.3.2≥ 2025.0, < 2026.2.3+2 more2026-09-30
CVE-2026-13046 [HIGH] CWE-502 CVE-2026-13046: A deserialization of untrusted data vulnerability in WatchGuard Fireware OS's SAML single sign-on se A deserialization of untrusted data vulnerability in WatchGuard Fireware OS's SAML single sign-on session handling (samld) allows an attacker who has already obtained the ability to write files on the appliance to execute arbitrary code in the context of the samld service by causing samld to load a maliciously crafted session file.
nvd
Watchguard Fireware Os vulnerabilities | cvebase