Junglewise Threat Intelligence

CVE-2025-13940: WatchGuard Fireware OS boot time system integrity check bypass

CVE-2025-13940 · Severity: medium · CVSS 5.5 · Published 2025-12-04

Technologies: Watchguard Fireware OS. Vendors: Watchguard.

Executive brief

WatchGuard Fireware OS is the operating system that runs on WatchGuard Firebox network security appliances, which protect corporate networks by filtering and controlling traffic. An attacker could bypass the system integrity check that runs at boot time, allowing malicious code or configuration changes to persist on the device without detection, and preventing the device from shutting down safely if tampering is detected.

Technical details

This is an Expected Behavior Violation (CWE-440) vulnerability in the WatchGuard Fireware OS boot-time system integrity check mechanism. An attacker can bypass the integrity verification that normally executes during device startup, which is designed to detect unauthorized firmware or system modifications. The vulnerability allows the device to continue operation even when the integrity check fails, preventing the Firebox from shutting down as designed. However, the on-demand integrity check in the Web UI will still correctly report failures. The vulnerability affects Fireware OS versions 2025.1 through 2025.1.2 and 12.8.1 through 12.11.4, and is fixed in versions 2025.1.3 and 12.11.5.

Affected products

  • WatchGuard Fireware OS 2025.1 through 2025.1.2, 12.8.1 through 12.11.4

Timeline

  • 2025-12-04: disclosed
  • 2025-12-04: patched: Fireware OS 2025.1.3 and 12.11.5 released

References

Related threats