Back Heise.De WatchGuard AP: Command Injection Vulnerabilities and Bypassable Authentication
Three security vulnerabilities slumber in WatchGuard’s access points, through which attackers can smuggle commands or bypass authentication. Updated firmware remedies the flaws, some of which are classified as critical risks.
WatchGuard warns of these in separate security advisories. An insufficient access control allows attackers on the network to gain a valid API session without prior authentication (CVE-2026-101891, CVSS4 9.3 , Risk “ critical ”). The internal API service of the WatchGuard AP allows attackers with network access to the AP to inject arbitrary shell commands that are executed in the operating system (CVE-2026-86102, CVSS4 9.3 , Risk “ critical ”). The third security vulnerability allows authenticated administrators to execute arbitrary operating system commands via manipulated input on the diagnostic command line (CVE-2026-87969, CVSS4 8.6 , Risk “ high ”).
WatchGuard does not provide more detailed information the security vulnerabilities, nor how attacks could be detected. Since the critical vulnerabilities allow exploitation without authentication merely with network access, IT managers should download and apply the firmware update as soon as possible. This minimizes the attack surface on the network.
The firmware of WatchGuard APs from version 1.0 is affected. Firmware 3.4.8 and newer no longer contain the security-relevant errors. WatchGuard points out that the company – at the time of the vulnerability report, i.e., until Monday of this week – is not aware of any exploitation of the flaws in the wild.
At the end of August, WatchGuard closed malware vulnerabilities in its security appliances with Firebox OS . Attackers could have fully compromised the appliances through the security flaws.
This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
