← Back

Watchguard

watchguard

106 CVEs • 114 products

Products (114)

Click to collapse
Toggle
Fireware
fireware
Soho Firewall
soho_firewall
Agent
agent
Firebox
firebox
Firebox Ii
firebox_ii
Epp Firmware
epp_firmware
Edr Firmware
edr_firmware
Epdr Firmware
epdr_firmware
Xcs
xcs
Serverlock
serverlock
Firebox 2500
firebox_2500
Firebox 4500
firebox_4500
Legacy Rssa
legacy_rssa
Soho
soho
Vclass
vclass
Server Center
server_center
Rapidstream
rapidstream
Hawkeye G
hawkeye_g
Fireware Xtm
fireware_xtm
Panda Dome
panda_dome
Ap200
ap200
Ap102
ap102
Ap100
ap100
Ap300
ap300
Xmt515
xmt515
Firebox M200
firebox_m200
Firebox M270
firebox_m270
Firebox M290
firebox_m290
Firebox M300
firebox_m300
Firebox M370
firebox_m370
Firebox M390
firebox_m390
Firebox M400
firebox_m400
Firebox M440
firebox_m440
Firebox M470
firebox_m470
Firebox M4800
firebox_m4800
Firebox M500
firebox_m500
Firebox M570
firebox_m570
Firebox M5800
firebox_m5800
Firebox M590
firebox_m590
Firebox M670
firebox_m670
Firebox M690
firebox_m690
Firebox T10
firebox_t10
Firebox T10 D
firebox_t10-d
Firebox T10 W
firebox_t10-w
Firebox T15
firebox_t15
Firebox T15 W
firebox_t15-w
Firebox T20
firebox_t20
Firebox T20 W
firebox_t20-w
Firebox T30
firebox_t30
Firebox T30 W
firebox_t30-w
Firebox T35
firebox_t35
Firebox T35 R
firebox_t35-r
Firebox T35 W
firebox_t35-w
Firebox T40
firebox_t40
Firebox T40 W
firebox_t40-w
Firebox T50
firebox_t50
Firebox T50 W
firebox_t50-w
Firebox T55
firebox_t55
Firebox T55 W
firebox_t55-w
Firebox T70
firebox_t70
Firebox T80
firebox_t80
Fireboxcloud
fireboxcloud
Fireboxv
fireboxv
Xtmv
xtmv
Epp
epp
Edr
edr
Epdr
epdr
Panda Ad360
panda_ad360
Fireboxt Nv5
fireboxt_nv5
Fireboxt T25
fireboxt_t25
Fireboxt T45
fireboxt_t45
Fireboxt T85
fireboxt_t85
Firebox M4600
firebox_m4600
Firebox M5600
firebox_m5600
Firebox Nv5
firebox_nv5

CVEs (106)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Watchguard
1Fireware
Jul 9, 2026
Jul 3, 2026
5.9 MEDIUM· v4
4.4 MEDIUM· v3
N/A· v2
In exception circumstances, WatchGuard Fireware OS on a FireCluster may use a hard-coded encryption key to encrypt saved credentials for Access Portal resources. This vulnerability affects Fireware OS 12.1 up to and inc...Show more
In exception circumstances, WatchGuard Fireware OS on a FireCluster may use a hard-coded encryption key to encrypt saved credentials for Access Portal resources. This vulnerability affects Fireware OS 12.1 up to and including 12.12 and 2025.1 up to and including 2026.2. This vulnerability does not affect devices that do not support the Access Portal feature or standalone Fireboxes not deployed in a FireCluster.Show less
1Watchguard
1Fireware
Jul 9, 2026
Jul 3, 2026
8.6 HIGH· v4
7.2 HIGH· v3
N/A· v2
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS wgagent process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the Management Web UI.This vulnera...Show more
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS wgagent process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the Management Web UI.This vulnerability affects Fireware OS 12.1 up to and including 12.12 and 2025.1 up to and including 2026.2.Show less
1Watchguard
1Fireware
Jul 9, 2026
Jul 3, 2026
8.6 HIGH· v4
7.2 HIGH· v3
N/A· v2
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS ikestubd process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the Management Web UI.This vulner...Show more
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS ikestubd process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the Management Web UI.This vulnerability affects Fireware OS 12.1 up to and including 12.12 and 2025.1 up to and including 2026.2.Show less
1Watchguard
1Fireware
Jul 9, 2026
Jul 3, 2026
4.8 MEDIUM· v4
4.8 MEDIUM· v3
N/A· v2
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS SIP Proxy module allows Stored XSS. This vulnerability is an additional unmitigated atta...Show more
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS SIP Proxy module allows Stored XSS. This vulnerability is an additional unmitigated attack path for CVE-2025-6947. This issue affects Fireware OS 12.0 up to and including 12.12, 12.5 up to and including 12.5.18, and 2025.1 up to and including 2026.2.Show less
1Watchguard
1Fireware
Jul 9, 2026
Jul 3, 2026
4.8 MEDIUM· v4
4.8 MEDIUM· v3
N/A· v2
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS spamBlocker module allows Stored XSS. This vulnerability is an additional unmitigated at...Show more
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS spamBlocker module allows Stored XSS. This vulnerability is an additional unmitigated attack path for CVE-2025-1071. This issue affects Fireware OS 12.0 up to and including 12.12, 12.5 up to and including 12.5.18, and 2025.1 up to and including 2026.2.Show less
1Watchguard
1Fireware
Jul 9, 2026
Jul 3, 2026
4.8 MEDIUM· v4
4.8 MEDIUM· v3
N/A· v2
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Autotask Technology Integration module) allows Stored XSS. This vulnerability is an add...Show more
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Autotask Technology Integration module) allows Stored XSS. This vulnerability is an additional unmitigated attack path for CVE-2025-13938. This issue affects Fireware OS 12.4 up to and including 12.12, 12.5 up to and including 12.5.18, and 2025.1 up to and including 2026.2.Show less
1Watchguard
1Fireware
Jul 9, 2026
Jul 3, 2026
4.8 MEDIUM· v4
4.8 MEDIUM· v3
N/A· v2
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (ConnectWise Technology Integration module) allows Stored XSS. This vulnerability is an...Show more
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (ConnectWise Technology Integration module) allows Stored XSS. This vulnerability is an additional unmitigated attack path for CVE-2025-13937. This issue affects Fireware OS 12.4 up to and including 12.12, 12.5 up to and including 12.5.18, and 2025.1 up to and including 2026.2.Show less
1Watchguard
1Fireware
Jul 9, 2026
Jul 3, 2026
4.8 MEDIUM· v4
4.8 MEDIUM· v3
N/A· v2
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Tigerpaw Technology Integration module) allows Stored XSS. This vulnerability is an add...Show more
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Tigerpaw Technology Integration module) allows Stored XSS. This vulnerability is an additional unmitigated attack path for CVE-2025-13936. This issue affects Fireware OS 12.4 up to and including 12.12, 12.5 up to and including 12.5.18, and 2025.1 up to and including 2026.2.Show less
1Watchguard
2Fireware
Mobile Vpn With Ssl
Jul 10, 2026
Jul 3, 2026
7.3 HIGH· v4
7.8 HIGH· v3
N/A· v2
A local privilege escalation vulnerability in the WatchGuard Mobile VPN with SSL client for Windows allows a local attacker to escalate their privileges to NT AUTHORITY\SYSTEM on the machine where the client is installed...Show more
A local privilege escalation vulnerability in the WatchGuard Mobile VPN with SSL client for Windows allows a local attacker to escalate their privileges to NT AUTHORITY\SYSTEM on the machine where the client is installed. This issue affects the Mobile VPN with SSL client for Windows up to and including 2026.2.Show less
1Watchguard
1Fireware
Jul 10, 2026
Jul 3, 2026
8.6 HIGH· v4
7.2 HIGH· v3
N/A· v2
A path traversal vulnerability in the WatchGuard Fireware OS Management Web UI allows a privileged authenticated attacker to write arbitrary files on the Firebox's filesystem. This vulnerability affects Fireware OS 1...Show more
A path traversal vulnerability in the WatchGuard Fireware OS Management Web UI allows a privileged authenticated attacker to write arbitrary files on the Firebox's filesystem. This vulnerability affects Fireware OS 11.0 up to and including 11.12.4_Update1, 12.0 up to and including 12.12 and 2025.1 up to and including 2026.2.Show less
1Watchguard
1Fireware
Jul 10, 2026
Jul 3, 2026
8.6 HIGH· v4
7.2 HIGH· v3
N/A· v2
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to execute arbitrary code via a specially crafted CLI command. This vulnerability affects Fireware OS 11....Show more
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to execute arbitrary code via a specially crafted CLI command. This vulnerability affects Fireware OS 11.0 up to and including 11.12.4_Update1, 12.0 up to and including 12.12 and 2025.1 up to and including 2026.2.Show less
1Watchguard
1Agent
Jun 17, 2026
May 6, 2026
8.5 HIGH· v4
7.8 HIGH· v3
N/A· v2
Uncontrolled Search Path Element vulnerability in WatchGuard Agent on Windows allows Using Malicious Files.This issue affects WatchGuard Agent before 1.25.03.0000.
1Watchguard
1Agent
Jun 17, 2026
May 6, 2026
8.5 HIGH· v4
7.8 HIGH· v3
N/A· v2
Use of Hard-coded Cryptographic Key vulnerability in WatchGuard Agent on Windows allows Inclusion of Code in Existing Process.This issue affects WatchGuard Agent: before 1.25.03.0000.
1Watchguard
1Agent
Jun 17, 2026
May 6, 2026
7.3 HIGH· v4
7.8 HIGH· v3
N/A· v2
Incorrect permission assignment for a resource in the patch management component of the WatchGuard Agent on Windows allows an authenticated local user to elevate their privileges to NT AUTHORITY\\SYSTEM.
1Watchguard
1Agent
Jun 17, 2026
May 6, 2026
7.1 HIGH· v4
6.5 MEDIUM· v3
N/A· v2
Stack-based Buffer Overflow vulnerability in the WatchGuard Agent discovery service on Windows allows Overflow Buffers. An unauthenticated attacker on the same local network could exploit this vulnerability to crash the...Show more
Stack-based Buffer Overflow vulnerability in the WatchGuard Agent discovery service on Windows allows Overflow Buffers. An unauthenticated attacker on the same local network could exploit this vulnerability to crash the agent service.Show less
1Watchguard
1Agent
Jun 17, 2026
May 6, 2026
7.1 HIGH· v4
6.5 MEDIUM· v3
N/A· v2
Stack-based Buffer Overflow vulnerability in the WatchGuard Agent discovery service on Windows allows Overflow Buffers. An unauthenticated attacker on the same local network could exploit this vulnerability to crash the...Show more
Stack-based Buffer Overflow vulnerability in the WatchGuard Agent discovery service on Windows allows Overflow Buffers. An unauthenticated attacker on the same local network could exploit this vulnerability to crash the agent service.Show less
1Watchguard
1Fireware
Jun 17, 2026
Mar 3, 2026
6.9 MEDIUM· v4
4.9 MEDIUM· v3
N/A· v2
A vulnerability in WatchGuard Fireware OS may allow an attacker to bypass the Fireware OS filesystem integrity check and maintain limited persistence via a maliciously-crafted firmware update package.This issue affects F...Show more
A vulnerability in WatchGuard Fireware OS may allow an attacker to bypass the Fireware OS filesystem integrity check and maintain limited persistence via a maliciously-crafted firmware update package.This issue affects Fireware OS 12.0 up to and including 12.11.7, 12.5.9 up to and including 12.5.16, and 2025.1 up to and including 2026.1.1.Show less
1Watchguard
1Fireware
Jun 17, 2026
Mar 3, 2026
5.1 MEDIUM· v4
6.1 MEDIUM· v3
N/A· v2
A reflected cross-site scripting (XSS) vulnerability in the Fireware OS Web UI enabled execution of malicious JavaScript in the context of an authenticated management user's browser when they click on a specially crafted...Show more
A reflected cross-site scripting (XSS) vulnerability in the Fireware OS Web UI enabled execution of malicious JavaScript in the context of an authenticated management user's browser when they click on a specially crafted link. This vulnerability affects Fireware OS 12.7 up to and including 12.11.7 and 2025.1 up to and including 2026.1.1.Show less
1Watchguard
1Fireware
Jun 17, 2026
Mar 3, 2026
8.6 HIGH· v4
7.2 HIGH· v3
N/A· v2
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow an authenticated privileged administrator to execute arbitrary code with root permissions via an exposed management interface. This vulnerability...Show more
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow an authenticated privileged administrator to execute arbitrary code with root permissions via an exposed management interface. This vulnerability affects Fireware OS 11.9 up to and including 11.12.4_Update1, 12.0 up to and including 12.11.7 and 2025.1 up to and including 2026.1.1.Show less
1Watchguard
1Fireware
Jun 17, 2026
Dec 19, 2025
9.3 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the Mobile User VPN with IKEv2 and the Branch Office V...Show more
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the Mobile User VPN with IKEv2 and the Branch Office VPN using IKEv2 when configured with a dynamic gateway peer.This vulnerability affects Fireware OS 11.10.2 up to and including 11.12.4_Update1, 12.0 up to and including 12.11.5 and 2025.1 up to and including 2025.1.3.Show less