Executive brief
WatchGuard Fireware OS is the operating system running on the company's Firebox firewalls, which protect corporate networks by filtering and managing traffic. An authenticated administrator with privileged access can exploit a buffer overflow vulnerability in the IPSec configuration interface to execute arbitrary code, potentially compromising the firewall and the networks it protects.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in the WatchGuard Fireware OS management CLI when processing IPSec configuration commands. The vulnerability is triggered via specially crafted IPSec configuration CLI commands and requires authentication with elevated (privileged user) credentials. Successful exploitation allows an authenticated administrator to execute arbitrary code with firewall privileges. Patches are available: Fireware OS 2025.1.3, 12.11.5, and 12.5.14 address this issue for their respective version lines.
Affected products
- WatchGuard Fireware OS 2025.1, 2025.0; 12.0 through 12.11.4; 11.0 through 11.12.4+541730 (fixed in 2025.1.3, 12.11.5, and patched 11.x versions)
Timeline
- 2025-12-04: disclosed: CVE-2025-12195 published
- 2025-12-04: patched: Patches released (Fireware OS 2025.1.3, 12.11.5, 12.5.14)