CVE-2022-26318

CVSS 9.8 - CRITICAL
Description

On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code, aka FBX-22786. This vulnerability impacts Fireware OS before 12.7.2_U2, 12.x before 12.1.3_U8, and 12.2.x through 12.5.x before 12.5.9_U2.

Affected Products
13
Vendor Product Version
watchguard fireware All versions
watchguard fireware All versions
watchguard fireware All versions
watchguard fireware 12.1.3
watchguard fireware 12.1.3
watchguard fireware 12.1.3
watchguard fireware 12.1.3
watchguard fireware 12.1.3
watchguard fireware 12.1.3
watchguard fireware 12.1.3
watchguard fireware 12.1.3
watchguard fireware 12.5.9
watchguard fireware 12.7.2
Weakness Types
NVD-CWE-Other
CVE Information
CVE ID:
CVE-2022-26318
Published:
2022-03-04
Modified:
2025-11-13
CVSS Score:
9.8
Severity:
CRITICAL
Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Vendors
watchguard
Quick Actions
CVSS Severity Scale
0.0 - 3.9 LOW
4.0 - 6.9 MEDIUM
7.0 - 8.9 HIGH
9.0 - 10.0 CRITICAL