Skip to content
CodeAuditAgent

CVE-2026-13371

An authenticated administrator can trigger a denial-of-service condition in the Fireware Management Web UI by sending malformed or crafted data to the put_data endpoint, which performs unsafe deserialization of the attacker-supplied input.

Weakness

An authenticated administrator can trigger a denial-of-service condition in the Fireware Management Web UI by sending malformed or crafted data to the put_data endpoint, which performs unsafe deserialization of the attacker-supplied input.

Affected products

  • watchguard fireware
  • watchguard firebox_m295
  • watchguard firebox_m395
  • watchguard firebox_m495
  • watchguard firebox_m595
  • watchguard firebox_m695
  • watchguard firebox_t115-w
  • watchguard firebox_t125

References

Find the bug before an attacker does.

Sign in with GitHub and run your first audit in under a minute. The free plan needs no credit card.