Executive brief
WatchGuard Firebox is a network firewall that protects corporate infrastructure. An authenticated administrator with both web and command-line access can exploit leftover diagnostic code to enable a debug shell, potentially gaining deep system access and the ability to modify firewall behavior or access sensitive configuration data.
Technical details
This vulnerability involves leftover debug code (CWE-489) in WatchGuard Firebox that allows an authenticated admin user to enable a diagnostic debug shell. The attack requires the attacker to have admin credentials and access to both the management WebUI and command-line interface, and involves uploading a platform and version-specific diagnostic package followed by executing a debug command. An attacker exploiting this can gain shell access to the firewall system with admin privileges. Patches are available: Fireware OS 12.11.3 for Default platforms and 12.5.13 for T15/T35 platforms.
Affected products
- WatchGuard Firebox Fireware OS 12.0 - 12.11.2 (Default); Fireware OS 12.0 - 12.5.12 (T15/T35)
Timeline
- 2025-10-24: disclosed
- 2025-10-24: patched: Fireware OS 12.11.3 and 12.5.13 available