OS Command Injection in Fireware OS - CVE-2022-26318
Published: December 16, 2025
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation. A remote unauthenticated attacker can send a specially crafted XML-RPC request to the /agent/ endpoint and execute arbitrary OS commands on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
How to mitigate CVE-2022-26318
Links to Public Exploits and PoC-codes
- Exploit #12202 - Watchguard-RCE-POC-CVE-2022-26318 (Watchguard RCE POC CVE-2022-26318) (December 16, 2025)
- Exploit #12201 - watchguard_cve-2022-26318 () (December 16, 2025)
- Exploit #12200 - CVE-2022-26318 () (December 16, 2025)
- Exploit #12199 - WatchGuard XTM Firebox Unauthenticated Remote Command Execution (December 16, 2025)