Description
A path traversal vulnerability in the Fireware OS WebUI management agent allows an authenticated administrator to read or list arbitrary files on the local filesystem by sending a specially crafted management request.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Fireware OS 12.5.21, Fireware OS 2026.3.2, Fireware OS 2026.2.3, Fireware OS 12.12.3
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://psirt.watchguard.com/CVE-2026-13224 |
|
History
Tue, 29 Sep 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A path traversal vulnerability in the Fireware OS WebUI management agent allows an authenticated administrator to read or list arbitrary files on the local filesystem by sending a specially crafted management request. | |
| Title | Fireware OS Path Traversal in WebUI Management Agent Allows Arbitrary Local File Read | |
| First Time appeared |
Watchguard
Watchguard fireware Os |
|
| Weaknesses | CWE-22 CWE-23 |
|
| CPEs | cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Watchguard
Watchguard fireware Os |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: WatchGuard
Published:
Updated: 2026-09-29T23:05:47.654Z
Reserved: 2026-06-24T16:02:02.488Z
Link: CVE-2026-13224
No data.
No data.
No data.
OpenCVE Enrichment
No data.