Junglewise Threat Intelligence

CVE-2025-12196: WatchGuard Fireware OS out-of-bounds write in CLI ping command

CVE-2025-12196 · Severity: high · CVSS 7.2 · Published 2025-12-04

Technologies: Watchguard Fireware OS. Vendors: Watchguard.

Executive brief

WatchGuard Fireware OS is the operating system running on WatchGuard Firebox appliances, which serve as network firewalls and security gateways protecting corporate networks. An authenticated privileged user can exploit an out-of-bounds write vulnerability in the management CLI's ping command by sending a specially crafted command, allowing them to execute arbitrary code on the firewall and potentially compromise network security or gain full control of the appliance.

Technical details

This is an out-of-bounds write vulnerability (CWE-787) affecting the CLI ping command handler in WatchGuard Fireware OS. The vulnerability requires an authenticated privileged user with CLI access to exploit; it cannot be triggered remotely by unauthenticated users. An attacker with administrative privileges can craft a malicious CLI command that triggers a buffer overflow, allowing arbitrary code execution with the privileges of the CLI process. Patches are available: Fireware OS 12.11.5 for default platforms and 12.5.14 for T15/T35 appliances. WatchGuard reports no known exploitation in the wild.

Affected products

  • WatchGuard Fireware OS Default: >= 12.0, < 12.11.5; T15/T35: >= 12.0, < 12.5.14

Timeline

  • 2025-12-04: disclosed
  • 2025-12-04: patched: Fireware OS 12.11.5 and 12.5.14 released

References

Related threats