Like letting a houseguest rewrite your home alarm system because they handed you a business card you never checked
CVE-2026-86131 is a code injection flaw in the BOVPN Over TLS client configuration handler on WatchGuard Firebox appliances running Fireware OS. When a Firebox configured in client mode connects to a remote Firebox in server mode, it consumes configuration data pushed by the server. Due to improper certificate validation (CWE-295) and unchecked inclusion of server-supplied functionality (CWE-829), a malicious or compromised remote VPN peer can inject arbitrary commands that execute as root on the connecting Firebox. Affected versions span the entire supported Fireware OS tree: 12.0–12.12.2, 12.0–12.5.20 (T15/T35 models), 2025.0–2026.2.2, and 2026.3.0–2026.3.1. Patches are available in 12.12.3, 12.5.21, 2026.2.3, and 2026.3.2.
WatchGuard assigned this a CVSS 4.0 score of 9.2 Critical, and that rating is honest. The prerequisite — attacker must control the remote VPN server or intercept the connection — looks like meaningful friction on paper, and the AT:P (Attack Prerequisites Present) bit in the CVSS vector acknowledges it. But the combination of broken TLS certificate validation (CWE-295) and an 8–23-character pre-shared key that is often static across tunnel lifetimes means that a network-positioned attacker can impersonate the server endpoint without forging a valid certificate. In hub-and-spoke BOVPN architectures, compromising a single branch Firebox cascades root access to the hub — and from there to every other spoke. The product under attack is a perimeter firewall by definition; root compromise here doesn't just pop a box, it erases the network boundary.
5 steps from start to impact.
Obtain position as VPN peer
fingerd stack buffer overflow patched in the same batch), or achieves a network-level man-in-the-middle position via BGP hijacking, DNS poisoning (if the BOVPN peer is configured with a hostname), or ARP spoofing within the same broadcast domain. The CWE-295 certificate validation failure means the victim client Firebox will accept the attacker's TLS session without verifying the certificate chain.- Network adjacency or upstream routing control (BGP/DNS), OR prior compromise of the remote Firebox VPN peer
- Knowledge of the BOVPN Over TLS pre-shared key (8–23 chars, often static)
- Requires either a prior foothold on the partner Firebox or a non-trivial network-level redirect (BGP hijack, DNS poisoning)
- Pre-shared key must be known or brute-forced; 8-char minimum key space is small but not instant over the network
Establish BOVPN Over TLS session as server
- Victim Firebox has an active BOVPN Over TLS client configuration pointing at the attacker-controlled IP/hostname
- PSK authentication succeeds
- Only Fireboxes configured with BOVPN Over TLS client mode are affected — IPSec-only or Mobile VPN configurations are not vulnerable
- The tunnel may not auto-reconnect instantly if the original peer was online and healthy
Inject code via server-pushed configuration
- Active BOVPN Over TLS session with the victim Firebox
- The Firebox client configuration handler processes server-pushed data
- No additional authentication or user interaction required at this stage
- No known content filtering or sandboxing on the configuration parser
Achieve root-level code execution
- Successful code injection from step 3
- None — once code injection succeeds, root execution is automatic
Cascade to hub-and-spoke topology
- Victim is a hub Firebox in a multi-site BOVPN Over TLS topology
- Spoke Fireboxes also run vulnerable Fireware OS versions
- Organizations using IPSec BOVPN instead of BOVPN Over TLS for some or all spokes are partially protected on those links
- Small single-site deployments with no BOVPN tunnels are not affected
- WAF / reverse proxy in front of the Firebox — BOVPN Over TLS operates on port 443 as a direct peer-to-peer VPN tunnel, not as an HTTP service. A WAF cannot inspect or filter OpenVPN-based traffic inside the TLS session.
- IDS/IPS signatures on the Firebox itself — The attack payload arrives inside the encrypted BOVPN Over TLS tunnel that the Firebox terminates. The Firebox's own IPS engine cannot inspect traffic destined for its own VPN configuration handler.
- Restricting management Web UI access — The management interface (port 8080/4118) and the BOVPN Over TLS data plane (port 443) are separate services. Locking down management access does not affect BOVPN tunnel establishment or the code injection vector.
- MFA on VPN authentication — BOVPN Over TLS is a site-to-site tunnel between Fireboxes using PSK authentication, not a user-facing VPN. MFA is not applicable to this tunnel type.
The supporting signals.
| In-the-Wild Exploitation | Not observed. WatchGuard states they are not aware of any exploitation in the wild. Not listed in CISA KEV as of 2026-09-30. |
|---|---|
| Proof-of-Concept Availability | No public PoC. No repositories found on GitHub named after CVE-2026-86131. Not indexed on pocindex.io. No ExploitDB or Nuclei template entries. Disclosed 2026-09-29 — expect PoC development within 30–60 days given the CVSS 9.2 rating and the ~117k exposed Firebox population. |
| EPSS Score | Not yet scored. CVE was published 2026-09-29; FIRST EPSS model has not yet ingested it. Expect initial scoring within 7 days. Historical WatchGuard RCE CVEs (e.g., CVE-2022-23176) reached >90th percentile EPSS within weeks of disclosure. |
| CISA KEV Status | Not listed as of 2026-09-30. Given no observed exploitation and same-day disclosure, KEV listing is not expected imminently but should be monitored. |
| CVSS Vector | CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N — Network-reachable, low complexity, but requires *attack prerequisites present* (AT:P), meaning the attacker needs a prior position as VPN peer or MitM. Full CIA impact on the vulnerable system; no downstream system impact scored. |
| Affected Versions | Fireware OS 12.0 – 12.12.2 (general), 12.0 – 12.5.20 (T15/T35 models), 2025.0 – 2026.2.2, 2026.3.0 – 2026.3.1. Essentially every supported Fireware branch. |
| Fixed Versions | 12.12.3, 12.5.21 (T15/T35), 2026.2.3, 2026.3.2. No distro backport considerations — Fireware is vendor-distributed firmware. |
| Internet Exposure | Shadowserver Foundation scans from Dec 2025 identified ~117,000–125,000 internet-exposed Firebox IPs globally (35,600 in US, 13,000 Germany, 11,300 Italy, 9,000 UK). Not all run BOVPN Over TLS, but the exposed management surface overlaps with BOVPN-capable units on port 443. |
| Disclosure & Credit | Reserved 2026-09-05, published 2026-09-29 by WatchGuard PSIRT. Credited to researcher btaol (also styled *btaolfinder*), who has previously reported WatchGuard Fireware vulnerabilities including IKEv2 flaws. |
| Related CVEs in Same Batch | 13 additional CVEs patched 2026-09-29: CVE-2026-81433 (fingerd stack overflow, CVSS 8.7), CVE-2026-86104 (login DoS, 8.7), CVE-2026-18145 (spamd overflow, 8.6), CVE-2026-13224 (path traversal, 8.2), CVE-2026-86128/86132/86133 (DoS variants, 8.2). The fingerd overflow (CVE-2026-81433) is a plausible *enabler* for this CVE's attack chain — compromise the remote Firebox first, then pivot via BOVPN. |
Sources.
- WatchGuard PSIRT Advisory — CVE-2026-86131
- SecurityOnline — WatchGuard Patches 14 Fireware OS Vulnerabilities
- Strix.ai — CVE-2026-86131 Analysis
- ThreatInt CVE Database — CVE-2026-86131
- INCIBE-CERT — CVE-2026-86131
- WatchGuard — About BOVPN Over TLS
- Cyberwarzone — 117,490+ Exposed WatchGuard Firewalls
- OffSeq Threat Radar — CVE-2026-86131
Why this verdict
- AT:P prerequisite is real but insufficient to drop below CRITICAL. The attacker must control the remote VPN peer or achieve network-level MitM. However, CWE-295 (broken certificate validation) means the MitM path does not require forging a valid TLS certificate — only a network position and the 8–23-char PSK. This is a meaningful but narrow gate, not a showstopper, especially for nation-state or advanced persistent actors targeting specific enterprises.
- Cascading compromise in hub-and-spoke BOVPN architecture compounds blast radius. A single compromised branch Firebox (potentially via the co-disclosed CVE-2026-81433 pre-auth buffer overflow) cascades to the hub, and from the hub to every spoke — turning one branch compromise into fleet-wide root access on every perimeter firewall.
- No exploitation in the wild and no public PoC provide a narrow timing window, not a severity reduction. This CVE was disclosed yesterday. The 117,000+ exposed Firebox population and the CVSS 9.2 rating will attract researcher and attacker attention rapidly. Historical WatchGuard vulns (CVE-2022-23176, Cyclops Blink) saw weaponization within weeks.
- Role multiplier: Firebox is canonically a network edge appliance (100% of installs). Root compromise of a perimeter firewall eliminates the network boundary. The attacker can: (a) intercept and modify all traffic traversing the appliance, (b) exfiltrate VPN credentials and PSKs for all tunnels, (c) disable logging and IPS, (d) pivot into every protected network segment, (e) in hub-and-spoke topologies, cascade to every branch office. Blast radius is fleet-scale. Per the high-value-role floor rule, this is a canonical network edge component → verdict floor is CRITICAL.
- No compensating detection layer exists on-box. Fireware OS has no host-based EDR, no integrity monitoring, no runtime application self-protection. Post-exploitation detection depends entirely on out-of-band monitoring (WatchGuard Cloud config drift, SIEM correlation), which most SMB Firebox customers do not have.
Why not higher?
A 9.0 is already near the top of the CRITICAL band. A 9.5+ or 10.0 would require a fully unauthenticated, zero-interaction, internet-facing exploit with no prerequisites. This CVE requires the attacker to either compromise the remote VPN peer first or achieve a network-level MitM position *and* possess the BOVPN PSK. The AT:P prerequisite is real friction that separates this from a scan-and-own like CVE-2022-23176 (Cyclops Blink).
Why not lower?
Firebox is a network edge appliance by definition — 100% of installs occupy the high-value role. Root compromise of the perimeter firewall is fleet-scale impact. The certificate validation bypass (CWE-295) substantially lowers the MitM barrier below what the bare description ('controls the remote VPN server') implies. The co-disclosed CVE-2026-81433 pre-auth buffer overflow provides a realistic enabler chain. Over 117,000 Firebox IPs are internet-exposed per Shadowserver. Dropping below CRITICAL would require evidence that <1% of Firebox installs use BOVPN Over TLS, and no such data exists.
Crowdsourced verification payload.
Run this script from any auditor workstation with SSH access to your Firebox appliances. The Firebox must have SSH management enabled. Usage: ./check_cve_2026_86131.sh <firebox_ip> [ssh_user] — defaults to admin user. Requires the ability to authenticate to the Firebox CLI.
#!/usr/bin/env bash
# CVE-2026-86131 - WatchGuard Fireware OS BOVPN Over TLS Code Injection
# Checks Fireware version against patched releases.
# Exit codes: 0=PATCHED, 1=VULNERABLE, 2=UNKNOWN
set -euo pipefail
FIREBOX="${1:?Usage: $0 <firebox_ip> [ssh_user]}"
SSH_USER="${2:-admin}"
# Fixed versions per branch:
# 2026.3.x -> >= 2026.3.2
# 2025.x / 2026.0-2.x -> >= 2026.2.3
# 12.6-12.x -> >= 12.12.3
# 12.5.x (T15/T35) -> >= 12.5.21
# 12.0-12.4.x -> VULNERABLE (no fix in that branch)
echo "[*] Querying Firebox at ${FIREBOX} as ${SSH_USER}..."
RAW=$(ssh -o ConnectTimeout=10 -o StrictHostKeyChecking=accept-new \
"${SSH_USER}@${FIREBOX}" "show sysinfo" 2>/dev/null) || {
echo "UNKNOWN - SSH connection to ${FIREBOX} failed"
exit 2
}
VERSION=$(echo "$RAW" | grep -iE 'firmware.version|fireware.version' | head -1 | \
sed 's/.*[: ] *//' | tr -d '[:space:]')
if [ -z "$VERSION" ]; then
echo "UNKNOWN - Could not parse firmware version from ${FIREBOX}"
exit 2
fi
echo "[*] Detected Fireware version: ${VERSION}"
# Also check if BOVPN Over TLS is configured
BOVPN_TLS=$(echo "$RAW" | grep -ci 'bovpn.*tls\|tls.*bovpn' || true)
if [ "$BOVPN_TLS" -eq 0 ]; then
echo "[i] Note: No BOVPN Over TLS reference found in sysinfo."
echo "[i] If BOVPN Over TLS is not configured, exposure is theoretical only."
fi
# Semantic version comparison: returns 0 if $1 >= $2
ver_gte() {
[ "$(printf '%s\n' "$1" "$2" | sort -V | head -n1)" = "$2" ]
}
case "$VERSION" in
2026.3.*)
if ver_gte "$VERSION" "2026.3.2"; then
echo "PATCHED - ${VERSION} >= 2026.3.2"; exit 0
else
echo "VULNERABLE - ${VERSION} < 2026.3.2 (CVE-2026-86131)"; exit 1
fi ;;
2026.*|2025.*)
if ver_gte "$VERSION" "2026.2.3"; then
echo "PATCHED - ${VERSION} >= 2026.2.3"; exit 0
else
echo "VULNERABLE - ${VERSION} < 2026.2.3 (CVE-2026-86131)"; exit 1
fi ;;
12.12.*|12.1[3-9].*|12.[2-9][0-9].*)
if ver_gte "$VERSION" "12.12.3"; then
echo "PATCHED - ${VERSION} >= 12.12.3"; exit 0
else
echo "VULNERABLE - ${VERSION} < 12.12.3 (CVE-2026-86131)"; exit 1
fi ;;
12.5.*)
if ver_gte "$VERSION" "12.5.21"; then
echo "PATCHED - ${VERSION} >= 12.5.21 (T15/T35 branch)"; exit 0
else
echo "VULNERABLE - ${VERSION} < 12.5.21 (CVE-2026-86131)"; exit 1
fi ;;
12.[6-9].*|12.1[0-1].*)
echo "VULNERABLE - ${VERSION} is below 12.12.3; upgrade required (CVE-2026-86131)"
exit 1 ;;
12.[0-4].*)
echo "VULNERABLE - ${VERSION} is in affected 12.x range; upgrade to >= 12.12.3 or >= 12.5.21 for T15/T35 (CVE-2026-86131)"
exit 1 ;;
*)
echo "UNKNOWN - Unrecognized version format: ${VERSION}"
exit 2 ;;
esac