A path traversal vulnerability in the Fireware OS WebUI management agent allows an authenticated administrator to read or list arbitrary files on the local filesystem by sending a specially crafted management request.
In order to exploit this vulnerability, an attacker must have network access to the Management Web UI.
WatchGuard is not aware of any exploitation of this vulnerability in the wild.
Fireware OS 12.5.21, Fireware OS 2026.3.2, Fireware OS 2026.2.3, Fireware OS 12.12.3