ZDI-26-501: WatchGuard FireWare OS sigd comp_start_cb Directory Traversal Arbitrary File Creation Vulnerability
Published Jul 29, 2026
·Updated
This vulnerability allows remote attackers to create arbitrary files on affected installations of WatchGuard FireWare OS. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-13054.
Affected Software
1 affected component
WatchGuard Fireware OS
Event History
Jul 29, 2026
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-26-501?
ZDI-26-501 has a CVSS rating of 7.2, indicating it is a high-severity vulnerability.
2
How do I fix ZDI-26-501?
To fix ZDI-26-501, update your WatchGuard FireWare OS to the latest version provided by the vendor.
3
What exploit conditions are necessary for ZDI-26-501?
ZDI-26-501 requires authentication to exploit, allowing remote attackers to create arbitrary files.
4
Which software is affected by ZDI-26-501?
ZDI-26-501 affects installations of WatchGuard FireWare OS.
5
What is the impact of ZDI-26-501?
The impact of ZDI-26-501 is that it allows remote attackers to create arbitrary files on the affected system.