Garmin WDU Authentication Bypass Vulnerability via Unauthenticated WebSocket APIs
Vulnerability
An authentication bypass vulnerability has been identified in the Garmin WDU web application, specifically in versions 1.1.4.6 and 2.5.0. The issue arises because the application only performs authentication within the client's browser, leaving WebSocket communications with the WDU server unprotected. This allows attackers to exploit the vulnerability by directly accessing the remote APIs available on the WebSocket, bypassing all authentication mechanisms.
Impact
Exploitation of this vulnerability allows for unauthorized access to the WDU's WebSocket APIs, potentially leading to unauthorized actions or data manipulation within the application.
Remediation
Users can update to Garmin WDU version 7.00, released on April 2, 2026, which addresses this vulnerability along with others. Instructions for downloading the update are available on the Garmin support website.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
