Executive brief
WatchGuard Fireware OS is the core operating system that powers WatchGuard Firebox firewalls, which protect corporate networks by inspecting and controlling traffic. An authenticated administrator with privileged access can exploit a buffer overflow vulnerability in the certificate request command to execute arbitrary code on the firewall, potentially allowing complete compromise of the device and access to network traffic it protects.
Technical details
This is an out-of-bounds write vulnerability (CWE-787) in the certificate daemon (certd) component of WatchGuard Fireware OS, triggered through specially crafted CLI commands. The vulnerability requires authenticated access with elevated privileges and network connectivity to the firewall's management interface. An attacker with admin credentials can send malformed certificate request commands via the CLI to overflow a buffer in the certd process, allowing arbitrary code execution with the privileges of the certd daemon. Patches are available in Fireware OS 2025.1.3, 12.11.5, and 12.5.14.
Affected products
- WatchGuard Fireware OS 2025.1.x (before 2025.1.3), 12.0–12.11.5
Timeline
- 2025-12-04: disclosed
- 2025-12-04: patched: Patches released: Fireware OS 2025.1.3, 12.11.5, and 12.5.14