PT-2022-1877 · Watchguard · Watchguard Xtm+2

Published

2022-02-28

·

Updated

2025-12-29

·

CVE-2022-26318

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions WatchGuard Firebox and XTM Appliances versions prior to 12.7.2 U2 WatchGuard Firebox and XTM Appliances versions prior to 12.1.3 U8 WatchGuard Firebox and XTM Appliances versions 12.2.x through 12.5.x prior to 12.5.9 U2
Description An unauthenticated user can execute arbitrary code on WatchGuard Firebox and XTM appliances. This issue, also known as FBX-22786, is due to insufficient input validation. The vulnerability allows a remote attacker to execute code.
Recommendations Update WatchGuard Firebox and XTM Appliances to version 12.7.2 U2 or later. Update WatchGuard Firebox and XTM Appliances to version 12.1.3 U8 or later. Update WatchGuard Firebox and XTM Appliances to version 12.5.9 U2 or later.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

BDU:2022-01382
CVE-2022-26318

Affected Products

Fireware Os
Watchguard Firebox
Watchguard Xtm