An LDAP Injection vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to retrieve sensitive information from a connected LDAP authentication server through an exposed authentication or management web interface. This vulnerability may also allow a remote attacker to authenticate as an LDAP user with a partial identifier if they additionally have that user's valid passphrase.This issue affects Fireware OS: from 12.0 through 12.11.6, from 12.5 through 12.5.15, from 2025.1 through 2026.0.
Metrics
Affected Vendors & Products
References
History
Fri, 30 Jan 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An LDAP Injection vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to retrieve sensitive information from a connected LDAP authentication server through an exposed authentication or management web interface. This vulnerability may also allow a remote attacker to authenticate as an LDAP user with a partial identifier if they additionally have that user's valid passphrase.This issue affects Fireware OS: from 12.0 through 12.11.6, from 12.5 through 12.5.15, from 2025.1 through 2026.0. | |
| Title | WatchGuard Firebox LDAP Injection | |
| First Time appeared |
Watchguard
Watchguard fireware Os |
|
| Weaknesses | CWE-90 | |
| CPEs | cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.0 cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.5 cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:2025.1 |
|
| Vendors & Products |
Watchguard
Watchguard fireware Os |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: WatchGuard
Published:
Updated: 2026-01-30T13:02:59.561Z
Reserved: 2026-01-27T17:23:30.578Z
Link: CVE-2026-1498
No data.
Status : Received
Published: 2026-01-30T13:15:54.560
Modified: 2026-01-30T13:15:54.560
Link: CVE-2026-1498
No data.
OpenCVE Enrichment
No data.