Junglewise Threat Intelligence

CVE-2025-4106: WatchGuard Firebox leftover debug code in diagnostic shell

CVE-2025-4106 · Severity: info · CVSS 8.9 · Published 2025-10-24

Technologies: Watchguard Firebox. Vendors: Watchguard.

Executive brief

WatchGuard Firebox is a network firewall that protects corporate infrastructure. An authenticated administrator with both web and command-line access can exploit leftover diagnostic code to enable a debug shell, potentially gaining deep system access and the ability to modify firewall behavior or access sensitive configuration data.

Technical details

This vulnerability involves leftover debug code (CWE-489) in WatchGuard Firebox that allows an authenticated admin user to enable a diagnostic debug shell. The attack requires the attacker to have admin credentials and access to both the management WebUI and command-line interface, and involves uploading a platform and version-specific diagnostic package followed by executing a debug command. An attacker exploiting this can gain shell access to the firewall system with admin privileges. Patches are available: Fireware OS 12.11.3 for Default platforms and 12.5.13 for T15/T35 platforms.

Affected products

  • WatchGuard Firebox Fireware OS 12.0 - 12.11.2 (Default); Fireware OS 12.0 - 12.5.12 (T15/T35)

Timeline

  • 2025-10-24: disclosed
  • 2025-10-24: patched: Fireware OS 12.11.3 and 12.5.13 available

References

Related threats