Description
This module exploits a buffer overflow at the administration interface (8080 or 4117) of WatchGuard Firebox and XTM appliances which is built from a cherrypy python backend sending XML-RPC requests to a C binary called wgagent using pre-authentication endpoint /agent/login. This vulnerability impacts Fireware OS before 12.7.2_U2, 12.x before 12.1.3_U8, and 12.2.x through 12.5.x before 12.5.9_U2. Successful exploitation results in remote code execution as user nobody.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use exploit/linux/http/watchguard_firebox_unauth_rce_cve_2022_26318msf undefined(watchguard_firebox_unauth_rce_cve_2022_26318) > show actions ...actions...msf undefined(watchguard_firebox_unauth_rce_cve_2022_26318) > set ACTION < action-name >msf undefined(watchguard_firebox_unauth_rce_cve_2022_26318) > show options ...show and set options...msf undefined(watchguard_firebox_unauth_rce_cve_2022_26318) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub