In exception circumstances, WatchGuard Fireware OS on a FireCluster may use a hard-coded encryption key to encrypt saved credentials for Access Portal resources.

This vulnerability affects Fireware OS 12.1 up to and including 12.12 and 2025.1 up to and including 2026.2. This vulnerability does not affect devices that do not support the Access Portal feature or standalone Fireboxes not deployed in a FireCluster.
Advisories

No advisories yet.

Fixes

Solution

Fireware OS 2026.2.1, Fireware OS 12.12.1


Workaround

No workaround given by the vendor.

History

Mon, 10 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description In exception circumstances, WatchGuard Fireware OS on a FireCluster may use a hard-coded encryption key to encrypt saved credentials for Access Portal resources. This vulnerability affects Fireware OS 12.1 up to and including 12.12 and 2025.1 up to and including 2026.2. This vulnerability does not affect devices that do not support the Access Portal feature or standalone Fireboxes not deployed in a FireCluster. In exception circumstances, WatchGuard Fireware OS on a FireCluster may use a hard-coded encryption key to encrypt saved credentials for Access Portal resources. This vulnerability does not affect devices that do not support the Access Portal feature or standalone Fireboxes not deployed in a FireCluster.
CPEs cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.1
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:2025.1
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:*
References

Mon, 06 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Description In exception circumstances, WatchGuard Fireware OS on a FireCluster may use a hard-coded encryption key to encrypt saved credentials for Access Portal resources. This vulnerability affects Fireware OS 12.1 up to and including 12.12 and 2025.1 up to and including 2026.2. This vulnerability does not affect devices that do not support the Access Portal feature or standalone Fireboxes not deployed in a FireCluster.
Title WatchGuard Firebox Hardcoded Fallback Encryption Key in Access Portal Resource Credential Database
First Time appeared Watchguard
Watchguard fireware Os
Weaknesses CWE-798
CPEs cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.1
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:2025.1
Vendors & Products Watchguard
Watchguard fireware Os
References
Metrics cvssV4_0

{'score': 5.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: WatchGuard

Published:

Updated: 2026-08-10T19:08:31.803Z

Reserved: 2026-06-29T14:36:27.889Z

Link: CVE-2026-13728

cve-icon Vulnrichment

Updated: 2026-07-06T14:55:57.806Z

cve-icon NVD

Status : Modified

Published: 2026-07-03T00:16:52.147

Modified: 2026-08-10T20:17:26.390

Link: CVE-2026-13728

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-10T23:15:05Z

Weaknesses