Junglewise Threat Intelligence

CVE-2025-12195: WatchGuard Fireware OS out-of-bounds write in CLI

CVE-2025-12195 · Severity: high · CVSS 7.2 · Published 2025-12-04

Technologies: Watchguard Fireware OS. Vendors: Watchguard.

Executive brief

WatchGuard Fireware OS is the operating system running on the company's Firebox firewalls, which protect corporate networks by filtering and managing traffic. An authenticated administrator with privileged access can exploit a buffer overflow vulnerability in the IPSec configuration interface to execute arbitrary code, potentially compromising the firewall and the networks it protects.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in the WatchGuard Fireware OS management CLI when processing IPSec configuration commands. The vulnerability is triggered via specially crafted IPSec configuration CLI commands and requires authentication with elevated (privileged user) credentials. Successful exploitation allows an authenticated administrator to execute arbitrary code with firewall privileges. Patches are available: Fireware OS 2025.1.3, 12.11.5, and 12.5.14 address this issue for their respective version lines.

Affected products

  • WatchGuard Fireware OS 2025.1, 2025.0; 12.0 through 12.11.4; 11.0 through 11.12.4+541730 (fixed in 2025.1.3, 12.11.5, and patched 11.x versions)

Timeline

  • 2025-12-04: disclosed: CVE-2025-12195 published
  • 2025-12-04: patched: Patches released (Fireware OS 2025.1.3, 12.11.5, 12.5.14)

References

Related threats