ZeroHour

CVE-2022-26318

KEVmass

Unauthenticated RCE in WatchGuard Firebox and XTM Fireware OS

CISA: WatchGuard Firebox and XTM Appliances Arbitrary Code Execution

CVSS 3.1
9.8 critical
EPSS
78%p100
Published
()
KEV added
AI analysis

CVE-2022-26318 (vendor tracker FBX-22786) is a critical (CVSS 9.8) unauthenticated arbitrary code execution vulnerability in Fireware OS running on WatchGuard Firebox and XTM security appliances. An unauthenticated remote attacker can trigger it by sending crafted requests to network-facing services on an affected appliance, requiring no credentials or user interaction. Successful exploitation allows execution of arbitrary code with high impact on confidentiality, integrity, and availability, typically yielding full control of the perimeter device and a foothold into the internal network behind it. Any organization running Fireware OS in the affected ranges — before 12.7.2_U2, 12.x before 12.1.3_U8, or 12.2.x through 12.5.x before 12.5.9_U2 — is exposed, a population dominated by SMB and mid-market perimeter firewall/VPN deployments. The flaw is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities Catalog on 2022-03-25, and press reporting of the period links Russian GRU (Sandworm) activity to exploitation of network edge devices of this kind.

What to do: Apply the vendor's updates per branch guidance: upgrade Fireware OS to 12.7.2_U2, 12.1.3_U8, or 12.5.9_U2 (or later) as applicable to your release train. Because the flaw is on CISA's KEV list, check whether the appliance's management or other interfaces are internet-exposed, review logs and configuration for signs of compromise, and consider a factory reset or re-image for appliances showing evidence of intrusion, since patching alone may not remove attacker persistence. Organizations in energy and other targeted sectors should prioritize remediation given reported GRU activity against edge devices.

Affected
WatchGuard Fireware OS (Firebox and XTM appliances)All versions before 12.7.2_U2
WatchGuard Fireware OS (Firebox and XTM appliances)12.x before 12.1.3_U8
WatchGuard Fireware OS (Firebox and XTM appliances)12.2.x through 12.5.x before 12.5.9_U2
Estimated exposure
mass~100,000-300,000 internet-exposed Firebox/XTM appliances per public scan counts; vendor-reported install base of 1M+ appliances — WatchGuard Firebox/XTM is a mainstream SMB perimeter firewall/VPN product line with a vendor-reported install base exceeding one million appliances, and public internet scans have counted on the order of 100,000+ exposed devices; both…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code, aka FBX-22786. This vulnerability impacts Fireware OS before 12.7.2_U2, 12.x before 12.1.3_U8, and 12.2.x through 12.5.x before 12.5.9_U2.

CISA Known Exploited Vulnerability
Affected
WatchGuard Firebox and XTM Appliances
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
watchguard
Products
fireware
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news