CVE-2022-26318
KEVmassUnauthenticated RCE in WatchGuard Firebox and XTM Fireware OS
CISA: WatchGuard Firebox and XTM Appliances Arbitrary Code Execution
CVE-2022-26318 (vendor tracker FBX-22786) is a critical (CVSS 9.8) unauthenticated arbitrary code execution vulnerability in Fireware OS running on WatchGuard Firebox and XTM security appliances. An unauthenticated remote attacker can trigger it by sending crafted requests to network-facing services on an affected appliance, requiring no credentials or user interaction. Successful exploitation allows execution of arbitrary code with high impact on confidentiality, integrity, and availability, typically yielding full control of the perimeter device and a foothold into the internal network behind it. Any organization running Fireware OS in the affected ranges — before 12.7.2_U2, 12.x before 12.1.3_U8, or 12.2.x through 12.5.x before 12.5.9_U2 — is exposed, a population dominated by SMB and mid-market perimeter firewall/VPN deployments. The flaw is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities Catalog on 2022-03-25, and press reporting of the period links Russian GRU (Sandworm) activity to exploitation of network edge devices of this kind.
What to do: Apply the vendor's updates per branch guidance: upgrade Fireware OS to 12.7.2_U2, 12.1.3_U8, or 12.5.9_U2 (or later) as applicable to your release train. Because the flaw is on CISA's KEV list, check whether the appliance's management or other interfaces are internet-exposed, review logs and configuration for signs of compromise, and consider a factory reset or re-image for appliances showing evidence of intrusion, since patching alone may not remove attacker persistence. Organizations in energy and other targeted sectors should prioritize remediation given reported GRU activity against edge devices.
| WatchGuard Fireware OS (Firebox and XTM appliances) | All versions before 12.7.2_U2 |
| WatchGuard Fireware OS (Firebox and XTM appliances) | 12.x before 12.1.3_U8 |
| WatchGuard Fireware OS (Firebox and XTM appliances) | 12.2.x through 12.5.x before 12.5.9_U2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code, aka FBX-22786. This vulnerability impacts Fireware OS before 12.7.2_U2, 12.x before 12.1.3_U8, and 12.2.x through 12.5.x before 12.5.9_U2.
- Affected
- WatchGuard Firebox and XTM Appliances
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- watchguard
- Products
- fireware
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H