{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-78008",
        "assignerOrgId": "5d1c2695-1a31-4499-88ae-e847036fd7e3",
        "state": "PUBLISHED",
        "assignerShortName": "WatchGuard",
        "dateReserved": "2026-08-21T21:46:38.156Z",
        "datePublished": "2026-08-27T23:24:32.515Z",
        "dateUpdated": "2026-08-27T23:24:32.515Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "5d1c2695-1a31-4499-88ae-e847036fd7e3",
                "shortName": "WatchGuard",
                "dateUpdated": "2026-08-27T23:24:32.515Z"
            },
            "title": "Fireware OS Authenticated Buffer Overflow in wgagent",
            "descriptions": [
                {
                    "lang": "en",
                    "value": "A buffer overflow vulnerability in the WatchGuard Fireware OS Management Web UI allows an authenticated administrator with network access to cause a denial of service (DoS) condition or potentially execute arbitrary code by sending specially crafted network traffic."
                }
            ],
            "affected": [
                {
                    "vendor": "WatchGuard",
                    "product": "Fireware OS",
                    "versions": [
                        {
                            "status": "affected",
                            "version": "2025.0",
                            "versionType": "custom",
                            "lessThan": "2026.2.2"
                        },
                        {
                            "status": "affected",
                            "version": "12.0",
                            "versionType": "custom",
                            "lessThan": "12.12.2"
                        }
                    ],
                    "defaultStatus": "unaffected",
                    "platforms": [
                        "Default"
                    ]
                },
                {
                    "vendor": "WatchGuard",
                    "product": "Fireware OS",
                    "versions": [
                        {
                            "status": "affected",
                            "version": "12.0",
                            "versionType": "custom",
                            "lessThan": "12.5.20"
                        }
                    ],
                    "defaultStatus": "unaffected",
                    "platforms": [
                        "T15/T35"
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://psirt.watchguard.com/CVE-2026-78008",
                    "tags": [
                        "vendor-advisory"
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "operator": "OR",
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "12.0",
                                    "versionEndExcluding": "12.5.20"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "2025.0",
                                    "versionEndExcluding": "2026.2.2"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "12.0",
                                    "versionEndExcluding": "12.12.2"
                                }
                            ]
                        }
                    ]
                }
            ],
            "metrics": [
                {
                    "cvssV4_0": {
                        "version": "4.0",
                        "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                        "baseScore": 8.6,
                        "baseSeverity": "HIGH"
                    }
                }
            ],
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "lang": "en",
                            "description": "CWE-787",
                            "type": "CWE",
                            "cweId": "CWE-787"
                        }
                    ]
                }
            ],
            "credits": [
                {
                    "lang": "en",
                    "value": "Cody Sixteen",
                    "type": "finder"
                }
            ],
            "configurations": [
                {
                    "lang": "en",
                    "value": "This vulnerability is exposed through the Fireware OS management interfaces (WSM and the Management Web UI). To reduce risk, do not expose the Fireware OS management interfaces to the internet.",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "<p>This vulnerability is exposed through the Fireware OS management interfaces (WSM and the Management Web UI). To reduce risk, do not expose the Fireware OS management interfaces to the internet.</p>"
                        }
                    ]
                }
            ],
            "solutions": [
                {
                    "lang": "en",
                    "value": "Fireware OS 2026.2.2, Fireware OS 12.12.2, Fireware OS 12.5.20",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "Fireware OS 2026.2.2, Fireware OS 12.12.2, Fireware OS 12.5.20"
                        }
                    ]
                }
            ],
            "workarounds": [
                {
                    "lang": "en",
                    "value": "Administrators should not expose the Firebox's management interfaces to untrusted network locations. See our Firebox Remote Management Best Practices (https://techsearch.watchguard.com/KB?type=Article&SFDCID=kA10H000000XeAtSAK&lang=en_US) KB article for guidance on how to secure remote management to a Firebox.",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "<p>Administrators should not expose the Firebox's management interfaces to untrusted network locations. See our <a href=\"https://techsearch.watchguard.com/KB?type=Article&amp;SFDCID=kA10H000000XeAtSAK&amp;lang=en_US\">Firebox Remote Management Best Practices</a> KB article for guidance on how to secure remote management to a Firebox.</p>"
                        }
                    ]
                }
            ],
            "exploits": [
                {
                    "lang": "en",
                    "value": "WatchGuard is not aware of any exploitation of this vulnerability in the wild.",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "WatchGuard is not aware of any exploitation of this vulnerability in the wild."
                        }
                    ]
                }
            ]
        }
    }
}