CVE-2026-13054
Severity CVSS v4.0:
HIGH
Type:
CWE-22
Path Traversal
Publication date:
03/07/2026
Last modified:
10/07/2026
Description
A path traversal vulnerability in the WatchGuard Fireware OS Management Web UI allows a privileged authenticated attacker to write arbitrary files on the Firebox&#39;s filesystem.<br />
<br />
<br />
<br />
<br />
This vulnerability affects Fireware OS 11.0 up to and including 11.12.4_Update1, 12.0 up to and including 12.12 and 2025.1 up to and including 2026.2.
Impact
Base Score 4.0
8.60
Severity 4.0
HIGH
Base Score 3.x
7.20
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:watchguard:fireware:*:*:*:*:*:*:*:* | 11.0 (including) | 12.12.1 (excluding) |
| cpe:2.3:h:watchguard:firebox_m270:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:watchguard:firebox_m290:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:watchguard:firebox_m370:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:watchguard:firebox_m390:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:watchguard:firebox_m440:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:watchguard:firebox_m4600:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:watchguard:firebox_m470:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:watchguard:firebox_m4800:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:watchguard:firebox_m5600:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:watchguard:firebox_m570:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:watchguard:firebox_m5800:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:watchguard:firebox_m590:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:watchguard:firebox_m670:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:watchguard:firebox_m690:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



