← Back to Feed CACHED · 2026-09-30 07:03:54 · CACHE_KEY CVE-2026-86131
CVE-2026-86131 · CWE-94 · Disclosed 2026-09-30

A code injection vulnerability in WatchGuard Fireware OS's BOVPN Over TLS client configuration handling

ASSESSED — NOISGATE
Vendor
—
—
—
Reassessed
—
—
—
Verdict: —
Do you agree?
01 · The Real Story

Like letting a houseguest rewrite your home alarm system because they handed you a business card you never checked

CVE-2026-86131 is a code injection flaw in the BOVPN Over TLS client configuration handler on WatchGuard Firebox appliances running Fireware OS. When a Firebox configured in client mode connects to a remote Firebox in server mode, it consumes configuration data pushed by the server. Due to improper certificate validation (CWE-295) and unchecked inclusion of server-supplied functionality (CWE-829), a malicious or compromised remote VPN peer can inject arbitrary commands that execute as root on the connecting Firebox. Affected versions span the entire supported Fireware OS tree: 12.0–12.12.2, 12.0–12.5.20 (T15/T35 models), 2025.0–2026.2.2, and 2026.3.0–2026.3.1. Patches are available in 12.12.3, 12.5.21, 2026.2.3, and 2026.3.2.

WatchGuard assigned this a CVSS 4.0 score of 9.2 Critical, and that rating is honest. The prerequisite — attacker must control the remote VPN server or intercept the connection — looks like meaningful friction on paper, and the AT:P (Attack Prerequisites Present) bit in the CVSS vector acknowledges it. But the combination of broken TLS certificate validation (CWE-295) and an 8–23-character pre-shared key that is often static across tunnel lifetimes means that a network-positioned attacker can impersonate the server endpoint without forging a valid certificate. In hub-and-spoke BOVPN architectures, compromising a single branch Firebox cascades root access to the hub — and from there to every other spoke. The product under attack is a perimeter firewall by definition; root compromise here doesn't just pop a box, it erases the network boundary.

"Malicious VPN peer gets root on your Firebox — your perimeter firewall is now the attacker's beachhead."
02 · The Attack Path

5 steps from start to impact.

STEP 01

Obtain position as VPN peer

The attacker compromises a remote Firebox acting as BOVPN Over TLS server (e.g., via CVE-2026-81433, the CVSS 8.7 pre-auth fingerd stack buffer overflow patched in the same batch), or achieves a network-level man-in-the-middle position via BGP hijacking, DNS poisoning (if the BOVPN peer is configured with a hostname), or ARP spoofing within the same broadcast domain. The CWE-295 certificate validation failure means the victim client Firebox will accept the attacker's TLS session without verifying the certificate chain.
Conditions required:
  • Network adjacency or upstream routing control (BGP/DNS), OR prior compromise of the remote Firebox VPN peer
  • Knowledge of the BOVPN Over TLS pre-shared key (8–23 chars, often static)
Where this breaks in practice:
  • Requires either a prior foothold on the partner Firebox or a non-trivial network-level redirect (BGP hijack, DNS poisoning)
  • Pre-shared key must be known or brute-forced; 8-char minimum key space is small but not instant over the network
Detection/coverage: Network anomaly detection may flag unexpected TLS renegotiation or certificate mismatch if the connection is monitored; Shodan/Censys can enumerate exposed Firebox management interfaces on port 443.
STEP 02

Establish BOVPN Over TLS session as server

The attacker's controlled endpoint accepts the client Firebox's BOVPN Over TLS connection on port 443. Because TLS certificate validation is broken (CWE-295), the client proceeds with the handshake despite the server presenting an untrusted certificate. The OpenVPN-based tunnel negotiation completes using the shared PSK, giving the attacker a fully authenticated server-side session.
Conditions required:
  • Victim Firebox has an active BOVPN Over TLS client configuration pointing at the attacker-controlled IP/hostname
  • PSK authentication succeeds
Where this breaks in practice:
  • Only Fireboxes configured with BOVPN Over TLS client mode are affected — IPSec-only or Mobile VPN configurations are not vulnerable
  • The tunnel may not auto-reconnect instantly if the original peer was online and healthy
Detection/coverage: Fireware logs will record the BOVPN tunnel establishment; SIEM rules can alert on tunnel partner IP changes or certificate fingerprint mismatches if custom logging is enabled.
STEP 03

Inject code via server-pushed configuration

With the BOVPN Over TLS session established, the attacker's server pushes crafted configuration data to the client Firebox. Due to CWE-829 (Inclusion of Functionality from Untrusted Control Sphere) and CWE-94 (Code Injection), the client-side configuration parser executes attacker-supplied commands without sanitization. The injected payload can contain arbitrary shell commands.
Conditions required:
  • Active BOVPN Over TLS session with the victim Firebox
  • The Firebox client configuration handler processes server-pushed data
Where this breaks in practice:
  • No additional authentication or user interaction required at this stage
  • No known content filtering or sandboxing on the configuration parser
Detection/coverage: No standard Firebox log entry distinguishes malicious from legitimate server-pushed configuration; host-based detection on Fireware OS is essentially nonexistent.
STEP 04

Achieve root-level code execution

The injected commands execute with root privileges on the Firebox appliance. The attacker now has full control: they can modify firewall policies, intercept all traffic traversing the appliance, exfiltrate VPN credentials and PSKs for other tunnels, install persistent backdoors, and disable logging. On a hub Firebox in a hub-and-spoke topology, the attacker gains access to route tables and PSKs for every connected spoke.
Conditions required:
  • Successful code injection from step 3
Where this breaks in practice:
  • None — once code injection succeeds, root execution is automatic
Detection/coverage: Post-compromise detection requires out-of-band integrity monitoring (e.g., WatchGuard Cloud configuration drift alerts, or comparing running config hashes against a known-good baseline). Standard SIEM ingestion of Fireware syslog will not catch root-level shell activity.
STEP 05

Cascade to hub-and-spoke topology

From the compromised hub Firebox, the attacker extracts BOVPN Over TLS PSKs and route configurations for all spoke Fireboxes. Because those spokes also have broken certificate validation (same CVE), the attacker can now impersonate the hub and push malicious configuration to every spoke simultaneously, achieving fleet-wide root compromise of all branch office perimeter firewalls in a single campaign.
Conditions required:
  • Victim is a hub Firebox in a multi-site BOVPN Over TLS topology
  • Spoke Fireboxes also run vulnerable Fireware OS versions
Where this breaks in practice:
  • Organizations using IPSec BOVPN instead of BOVPN Over TLS for some or all spokes are partially protected on those links
  • Small single-site deployments with no BOVPN tunnels are not affected
Detection/coverage: Mass simultaneous tunnel renegotiation across all spokes would produce an anomalous log pattern in WatchGuard Cloud or a centralized SIEM, but most orgs do not alert on this.
03 · Compensating Control

1
CRITICAL 9.0→IGNORE 0.0
SEVERITY REDUCED
Disable BOVPN Over TLS and switch to IPSec BOVPN immediately — IPSec BOVPN uses a completely different protocol path (IKEv1/IKEv2 + ESP) and is not affected by this CVE's code injection in the TLS client configuration handler. WatchGuard documentation recommends BOVPN Over TLS only when 'the network cannot pass IPSec traffic.' For most enterprise deployments, IPSec BOVPN is the superior choice regardless of this CVE. Deploy this change within 3 days per the noisgate mitigation SLA for CRITICAL severity. This completely eliminates the attack surface.
2
CRITICAL 9.0→HIGH 7.5
SEVERITY REDUCED
Pin BOVPN Over TLS peers to static IPs and block dynamic gateway peers — If BOVPN Over TLS cannot be replaced, configure all tunnels with static IP addresses rather than hostnames, and disable dynamic peer discovery. Create a WatchGuard alias containing only the known-good IP addresses of legitimate BOVPN peers, add explicit firewall policies allowing only those addresses on port 443, and disable the default built-in VPN policies. This eliminates the DNS-poisoning MitM vector and forces the attacker to compromise the actual peer Firebox or hijack the specific IP via BGP. Deploy within 3 days per the noisgate mitigation SLA.
3
CRITICAL 9.0→CRITICAL 8.5
Rotate BOVPN Over TLS pre-shared keys to maximum length (23 chars) — The PSK is the remaining authentication gate after the broken TLS certificate validation. Use the maximum 23-character key with full entropy (random alphanumeric + special chars). Rotate keys across all BOVPN Over TLS tunnels immediately. This does not fix the vulnerability but raises the bar for MitM-based exploitation. Deploy within 3 days alongside IP pinning.
4
CRITICAL 9.0→IGNORE 0.0
SEVERITY REDUCED
Apply Fireware OS patches (12.12.3, 12.5.21, 2026.2.3, or 2026.3.2) — The definitive fix. WatchGuard has released patched firmware for all supported branches. Schedule firmware upgrades within maintenance windows. For CRITICAL severity, the noisgate remediation SLA is ≤90 days. Given no active exploitation yet, a staged rollout (pilot → branch offices → hub firewalls) over 2–4 weeks is acceptable if compensating controls are in place.
5
CRITICAL 9.0→CRITICAL 8.8
Deploy out-of-band configuration integrity monitoring — Enable WatchGuard Cloud configuration drift alerts or export Firebox configs to a SIEM and hash-compare against known-good baselines on a 15-minute interval. This does not prevent exploitation but provides post-compromise detection capability where none exists on-box. Deploy within 3 days as a detection compensating control.
What doesn't work
  • WAF / reverse proxy in front of the Firebox — BOVPN Over TLS operates on port 443 as a direct peer-to-peer VPN tunnel, not as an HTTP service. A WAF cannot inspect or filter OpenVPN-based traffic inside the TLS session.
  • IDS/IPS signatures on the Firebox itself — The attack payload arrives inside the encrypted BOVPN Over TLS tunnel that the Firebox terminates. The Firebox's own IPS engine cannot inspect traffic destined for its own VPN configuration handler.
  • Restricting management Web UI access — The management interface (port 8080/4118) and the BOVPN Over TLS data plane (port 443) are separate services. Locking down management access does not affect BOVPN tunnel establishment or the code injection vector.
  • MFA on VPN authentication — BOVPN Over TLS is a site-to-site tunnel between Fireboxes using PSK authentication, not a user-facing VPN. MFA is not applicable to this tunnel type.
04 · Intelligence Metadata

The supporting signals.

In-the-Wild ExploitationNot observed. WatchGuard states they are not aware of any exploitation in the wild. Not listed in CISA KEV as of 2026-09-30.
Proof-of-Concept AvailabilityNo public PoC. No repositories found on GitHub named after CVE-2026-86131. Not indexed on pocindex.io. No ExploitDB or Nuclei template entries. Disclosed 2026-09-29 — expect PoC development within 30–60 days given the CVSS 9.2 rating and the ~117k exposed Firebox population.
EPSS ScoreNot yet scored. CVE was published 2026-09-29; FIRST EPSS model has not yet ingested it. Expect initial scoring within 7 days. Historical WatchGuard RCE CVEs (e.g., CVE-2022-23176) reached >90th percentile EPSS within weeks of disclosure.
CISA KEV StatusNot listed as of 2026-09-30. Given no observed exploitation and same-day disclosure, KEV listing is not expected imminently but should be monitored.
CVSS VectorCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N — Network-reachable, low complexity, but requires *attack prerequisites present* (AT:P), meaning the attacker needs a prior position as VPN peer or MitM. Full CIA impact on the vulnerable system; no downstream system impact scored.
Affected VersionsFireware OS 12.0 – 12.12.2 (general), 12.0 – 12.5.20 (T15/T35 models), 2025.0 – 2026.2.2, 2026.3.0 – 2026.3.1. Essentially every supported Fireware branch.
Fixed Versions12.12.3, 12.5.21 (T15/T35), 2026.2.3, 2026.3.2. No distro backport considerations — Fireware is vendor-distributed firmware.
Internet ExposureShadowserver Foundation scans from Dec 2025 identified ~117,000–125,000 internet-exposed Firebox IPs globally (35,600 in US, 13,000 Germany, 11,300 Italy, 9,000 UK). Not all run BOVPN Over TLS, but the exposed management surface overlaps with BOVPN-capable units on port 443.
Disclosure & CreditReserved 2026-09-05, published 2026-09-29 by WatchGuard PSIRT. Credited to researcher btaol (also styled *btaolfinder*), who has previously reported WatchGuard Fireware vulnerabilities including IKEv2 flaws.
Related CVEs in Same Batch13 additional CVEs patched 2026-09-29: CVE-2026-81433 (fingerd stack overflow, CVSS 8.7), CVE-2026-86104 (login DoS, 8.7), CVE-2026-18145 (spamd overflow, 8.6), CVE-2026-13224 (path traversal, 8.2), CVE-2026-86128/86132/86133 (DoS variants, 8.2). The fingerd overflow (CVE-2026-81433) is a plausible *enabler* for this CVE's attack chain — compromise the remote Firebox first, then pivot via BOVPN.

Sources.

  1. WatchGuard PSIRT Advisory — CVE-2026-86131
  2. SecurityOnline — WatchGuard Patches 14 Fireware OS Vulnerabilities
  3. Strix.ai — CVE-2026-86131 Analysis
  4. ThreatInt CVE Database — CVE-2026-86131
  5. INCIBE-CERT — CVE-2026-86131
  6. WatchGuard — About BOVPN Over TLS
  7. Cyberwarzone — 117,490+ Exposed WatchGuard Firewalls
  8. OffSeq Threat Radar — CVE-2026-86131
05 · The Call

Final Verdict
= UNCHANGED to CRITICAL (9.0/10)

Why this verdict

  • AT:P prerequisite is real but insufficient to drop below CRITICAL. The attacker must control the remote VPN peer or achieve network-level MitM. However, CWE-295 (broken certificate validation) means the MitM path does not require forging a valid TLS certificate — only a network position and the 8–23-char PSK. This is a meaningful but narrow gate, not a showstopper, especially for nation-state or advanced persistent actors targeting specific enterprises.
  • Cascading compromise in hub-and-spoke BOVPN architecture compounds blast radius. A single compromised branch Firebox (potentially via the co-disclosed CVE-2026-81433 pre-auth buffer overflow) cascades to the hub, and from the hub to every spoke — turning one branch compromise into fleet-wide root access on every perimeter firewall.
  • No exploitation in the wild and no public PoC provide a narrow timing window, not a severity reduction. This CVE was disclosed yesterday. The 117,000+ exposed Firebox population and the CVSS 9.2 rating will attract researcher and attacker attention rapidly. Historical WatchGuard vulns (CVE-2022-23176, Cyclops Blink) saw weaponization within weeks.
  • Role multiplier: Firebox is canonically a network edge appliance (100% of installs). Root compromise of a perimeter firewall eliminates the network boundary. The attacker can: (a) intercept and modify all traffic traversing the appliance, (b) exfiltrate VPN credentials and PSKs for all tunnels, (c) disable logging and IPS, (d) pivot into every protected network segment, (e) in hub-and-spoke topologies, cascade to every branch office. Blast radius is fleet-scale. Per the high-value-role floor rule, this is a canonical network edge component → verdict floor is CRITICAL.
  • No compensating detection layer exists on-box. Fireware OS has no host-based EDR, no integrity monitoring, no runtime application self-protection. Post-exploitation detection depends entirely on out-of-band monitoring (WatchGuard Cloud config drift, SIEM correlation), which most SMB Firebox customers do not have.

Why not higher?

A 9.0 is already near the top of the CRITICAL band. A 9.5+ or 10.0 would require a fully unauthenticated, zero-interaction, internet-facing exploit with no prerequisites. This CVE requires the attacker to either compromise the remote VPN peer first or achieve a network-level MitM position *and* possess the BOVPN PSK. The AT:P prerequisite is real friction that separates this from a scan-and-own like CVE-2022-23176 (Cyclops Blink).

Why not lower?

Firebox is a network edge appliance by definition — 100% of installs occupy the high-value role. Root compromise of the perimeter firewall is fleet-scale impact. The certificate validation bypass (CWE-295) substantially lowers the MitM barrier below what the bare description ('controls the remote VPN server') implies. The co-disclosed CVE-2026-81433 pre-auth buffer overflow provides a realistic enabler chain. Over 117,000 Firebox IPs are internet-exposed per Shadowserver. Dropping below CRITICAL would require evidence that <1% of Firebox installs use BOVPN Over TLS, and no such data exists.

06 · Verification

Crowdsourced verification payload.

Run this script from any auditor workstation with SSH access to your Firebox appliances. The Firebox must have SSH management enabled. Usage: ./check_cve_2026_86131.sh <firebox_ip> [ssh_user] — defaults to admin user. Requires the ability to authenticate to the Firebox CLI.

noisgate-verify.sh
BASHREAD-ONLYSAFE
#!/usr/bin/env bash
# CVE-2026-86131 - WatchGuard Fireware OS BOVPN Over TLS Code Injection
# Checks Fireware version against patched releases.
# Exit codes: 0=PATCHED, 1=VULNERABLE, 2=UNKNOWN

set -euo pipefail

FIREBOX="${1:?Usage: $0 <firebox_ip> [ssh_user]}"
SSH_USER="${2:-admin}"

# Fixed versions per branch:
#   2026.3.x  -> >= 2026.3.2
#   2025.x / 2026.0-2.x -> >= 2026.2.3
#   12.6-12.x -> >= 12.12.3
#   12.5.x (T15/T35) -> >= 12.5.21
#   12.0-12.4.x -> VULNERABLE (no fix in that branch)

echo "[*] Querying Firebox at ${FIREBOX} as ${SSH_USER}..."
RAW=$(ssh -o ConnectTimeout=10 -o StrictHostKeyChecking=accept-new \
  "${SSH_USER}@${FIREBOX}" "show sysinfo" 2>/dev/null) || {
  echo "UNKNOWN - SSH connection to ${FIREBOX} failed"
  exit 2
}

VERSION=$(echo "$RAW" | grep -iE 'firmware.version|fireware.version' | head -1 | \
  sed 's/.*[: ] *//' | tr -d '[:space:]')

if [ -z "$VERSION" ]; then
  echo "UNKNOWN - Could not parse firmware version from ${FIREBOX}"
  exit 2
fi

echo "[*] Detected Fireware version: ${VERSION}"

# Also check if BOVPN Over TLS is configured
BOVPN_TLS=$(echo "$RAW" | grep -ci 'bovpn.*tls\|tls.*bovpn' || true)
if [ "$BOVPN_TLS" -eq 0 ]; then
  echo "[i] Note: No BOVPN Over TLS reference found in sysinfo."
  echo "[i] If BOVPN Over TLS is not configured, exposure is theoretical only."
fi

# Semantic version comparison: returns 0 if $1 >= $2
ver_gte() {
  [ "$(printf '%s\n' "$1" "$2" | sort -V | head -n1)" = "$2" ]
}

case "$VERSION" in
  2026.3.*)
    if ver_gte "$VERSION" "2026.3.2"; then
      echo "PATCHED - ${VERSION} >= 2026.3.2"; exit 0
    else
      echo "VULNERABLE - ${VERSION} < 2026.3.2 (CVE-2026-86131)"; exit 1
    fi ;;
  2026.*|2025.*)
    if ver_gte "$VERSION" "2026.2.3"; then
      echo "PATCHED - ${VERSION} >= 2026.2.3"; exit 0
    else
      echo "VULNERABLE - ${VERSION} < 2026.2.3 (CVE-2026-86131)"; exit 1
    fi ;;
  12.12.*|12.1[3-9].*|12.[2-9][0-9].*)
    if ver_gte "$VERSION" "12.12.3"; then
      echo "PATCHED - ${VERSION} >= 12.12.3"; exit 0
    else
      echo "VULNERABLE - ${VERSION} < 12.12.3 (CVE-2026-86131)"; exit 1
    fi ;;
  12.5.*)
    if ver_gte "$VERSION" "12.5.21"; then
      echo "PATCHED - ${VERSION} >= 12.5.21 (T15/T35 branch)"; exit 0
    else
      echo "VULNERABLE - ${VERSION} < 12.5.21 (CVE-2026-86131)"; exit 1
    fi ;;
  12.[6-9].*|12.1[0-1].*)
    echo "VULNERABLE - ${VERSION} is below 12.12.3; upgrade required (CVE-2026-86131)"
    exit 1 ;;
  12.[0-4].*)
    echo "VULNERABLE - ${VERSION} is in affected 12.x range; upgrade to >= 12.12.3 or >= 12.5.21 for T15/T35 (CVE-2026-86131)"
    exit 1 ;;
  *)
    echo "UNKNOWN - Unrecognized version format: ${VERSION}"
    exit 2 ;;
esac
Peer Review

What defenders are saying.

Submit a review attribution: handle + country only
0 flags selected · stored anonymously