WGSA-2021-00005

WatchGuard Firebox WebUI Business Logic Vulnerability

High Published 2021-12-30Updated 2026-07-27

Summary #

The Firebox WebUI has a business logic flaw that could allow an attacker to obtain a limited authenticated session on the system via exposed management access.

CVE identifiers #

No CVE identifiers are associated with this advisory.

Product status #

ProductAffectedNot affected
Fireware OS
Default >= 12.0, < 12.7.2-b652282>= 12.7.2-b652282
T15/T35 >= 12.5.0, < 12.5.9-b652189>= 12.5.9-b652189
FIPS >= 12.3.1, < 12.3.1-b652336>= 12.3.1-b652336

Solution #

Fireware OS 12.7.2_Update1, Fireware OS 12.5.9_Update1, Fireware OS 12.3.1_Update2

References #