Garmin WDU Authentication Bypass Vulnerability via Unauthenticated WebSocket APIs

Vulnerability

An authentication bypass vulnerability has been identified in the Garmin WDU web application, specifically in versions 1.1.4.6 and 2.5.0. The issue arises because the application only performs authentication within the client's browser, leaving WebSocket communications with the WDU server unprotected. This allows attackers to exploit the vulnerability by directly accessing the remote APIs available on the WebSocket, bypassing all authentication mechanisms.

Impact

Exploitation of this vulnerability allows for unauthorized access to the WDU's WebSocket APIs, potentially leading to unauthorized actions or data manipulation within the application.

Remediation

Users can update to Garmin WDU version 7.00, released on April 2, 2026, which addresses this vulnerability along with others. Instructions for downloading the update are available on the Garmin support website.

Added: May 13, 2026, 9:36 PM
Updated: May 13, 2026, 9:36 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
4.9
remediation
0.0
relevance
8.2
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.