WatchGuard Firebox and XTM appliances allow an unauthenticated remote attacker to retrieve sensitive authentication server settings by sending a malicious request to exposed authentication endpoints. This is fixed in Fireware OS 12.8.1, 12.5.10, and 12.1.4.
- https://www.ambionics.io/blog/hacking-watchguard-firewalls
- https://github.com/ARPSyndicate/cvemon
- https://github.com/AlexRogalskiy/AlexRogalskiy
- https://github.com/pipiscrew/timeline