WGSA-2021-00001

WatchGuard Firebox Privilege Escalation Vulnerability

High Published 2021-08-02Updated 2026-07-27

Summary #

*Updated September 5 2025: Updated to clarify Fireware OS 12.3.1 Update 2 (FIPS-certified release) resolves this issue*

Firebox and XTM appliances have a privilege escalation vulnerability that could allow an authenticated management user with Device Monitor permissions to execute management commands and access Firebox resources as a Device Management user.

CVE identifiers #

No CVE identifiers are associated with this advisory.

Product status #

ProductAffectedNot affected
Fireware OS
Default >= 12.0, < 12.7.1>= 12.7.1
T15/T35 >= 12.5.0, < 12.5.8>= 12.5.8
FIPS >= 12.3.1, < 12.3.1-B675192>= 12.3.1-B675192

Solution #

Fireware OS 12.7.1, Fireware OS 12.5.8, Fireware OS 12.3.1-B675192

References #