Fireware OS Stack-Based Buffer Overflow in Mobile Security epm Endpoint
Summary #
A stack-based buffer overflow in the epm (Endpoint Protection Manager) service used by the deprecated Mobile Security feature in WatchGuard Fireware OS allows an unauthenticated remote attacker to execute arbitrary code.
Impact: A network-adjacent attacker with access to a trusted interface can send a specially crafted JSON-RPC request to the epm service to overflow a stack buffer, overwrite the saved return address, and execute arbitrary code with root privileges without authentication. The lack of a stack canary and use of a non-PIE binary make exploitation via return-oriented programming straightforward, and even unsuccessful exploitation attempts can crash the epm process, causing a denial of service until it is respawned.
Product status #
| Product | Affected | Not affected |
|---|---|---|
| Fireware OS | ||
| Default | >= 2025.0, < 2026.2.2, >= 12.0, < 12.12.2 | >= 2026.2.2, >= 12.12.2 |
| T15/T35 | >= 12.0, < 12.5.20 | >= 12.5.20 |
Weakness Type and Impact #
Exploitation Status #
Solution #
References #
Credits #
- Mat Powell of TrendAI Zero Day Initiativefinder