CVE-2026-13054: WatchGuard Firebox Arbitrary File Write via Path Traversal in Management Web UI
A path traversal vulnerability in the WatchGuard Fireware OS Management Web UI allows a privileged authenticated attacker to write arbitrary files on the Firebox's filesystem.
This vulnerability affects Fireware OS 11.0 up to and including 11.12.4Update1, 12.0 up to and including 12.12 and 2025.1 up to and including 2026.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13054?
CVE-2026-13054 has a high severity rating of 8.6 based on the CVSS scoring criteria.
How do I fix CVE-2026-13054?
To fix CVE-2026-13054, update your WatchGuard Fireware OS to a version later than 12.12.4_Update1.
What systems are affected by CVE-2026-13054?
CVE-2026-13054 affects WatchGuard Fireware OS versions from 11.0 up to and including 12.12.4_Update1 and 2025.1.
What type of vulnerability is CVE-2026-13054?
CVE-2026-13054 is a path traversal vulnerability that allows arbitrary file writes through the Management Web UI.
Who can exploit CVE-2026-13054?
CVE-2026-13054 can be exploited by a privileged authenticated attacker.