Junglewise Threat Intelligence

CVE-2025-1547: WatchGuard Fireware OS stack overflow in certificate request command

CVE-2025-1547 · Severity: high · CVSS 7.2 · Published 2025-12-04

Technologies: Watchguard Fireware OS. Vendors: Watchguard.

Executive brief

WatchGuard Fireware OS is the operating system that powers WatchGuard Firebox network security appliances used to protect enterprise networks. An authenticated administrator with privileged access can exploit a stack-based buffer overflow in the certificate request command to execute arbitrary code on the firewall, potentially gaining full control of the device and the networks it protects.

Technical details

This is a stack-based buffer overflow vulnerability (CWE-121) in the certificate request command processing within WatchGuard Fireware OS. The vulnerability exists in the CLI management interface and requires authentication with privileged administrator credentials. An authenticated attacker can send specially crafted CLI commands to overflow a stack buffer and achieve arbitrary code execution. The vulnerability affects Fireware OS versions 12.0 through 12.11.3 on Default models and 12.0 through 12.5.12 on T15/T35 models; patches are available (12.11.3 and 12.5.13 respectively). This vulnerability does not affect the default network-facing services and requires CLI access, which is typically restricted to administrative networks.

Affected products

  • WatchGuard Fireware OS 12.0 through 12.11.3 (Default models); 12.0 through 12.5.12 (T15/T35 models)

Timeline

  • 2025-12-04: disclosed
  • 2025-12-04: patched: Fixes released as Fireware OS 12.11.3 and 12.5.13
  • 2026-08-10: other: Advisory updated

References

Related threats