CVE-2025-4106 Details
Description
An authenticated admin user with access to both the management WebUI and command line interface on a Firebox can enable a diagnostic debug shell by uploading a platform and version-specific diagnostic package and executing a leftover diagnostic command.
A vulnerability exists in WatchGuard Firebox devices running Fireware OS versions 12.0 prior to 12.11.2. An authenticated admin user with access to both the management WebUI and command line interface can exploit this vulnerability by uploading a platform and version-specific diagnostic package. After the package is uploaded, the user can execute a leftover diagnostic command to enable a diagnostic debug shell.
Users can upgrade to Fireware OS 12.11.3 or, for T15 and T35 models, to Fireware OS 12.5.13.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Oct 24, 2025CISA-ADP
Assessed Oct 28, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://psirt.watchguard.com/CVE-2025-4106 | WatchGuard Technologies, Inc. | |
| https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2025-00010 | WatchGuard Technologies, Inc. | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-489 | Active Debug Code | WatchGuard Technologies, Inc. |
Affected Products
| Product | Versions |
|---|---|
| WatchGuard Firebox | All versions |
CPE
Remediation
| |
| WatchGuard Fireware OS | >= 12, <= 12.11.2 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 8, 2026 | CVE Modified | WatchGuard Technologies, Inc. |
| Jun 17, 2026 | CVE Modified | WatchGuard Technologies, Inc. |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 24, 2025 | New CVE Received | WatchGuard Technologies, Inc. |
Volerion