CVE-2025-12026: WatchGuard Firebox Authenticated Out of Bounds Write in certd
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS’s certificate request command could allow an authenticated privileged user to execute arbitrary code via specially crafted CLI commands.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WatchGuard Fireware OSto a version that resolves this vulnerability.Fixed in 2025.1.3 - Upgrade
Upgrade
WatchGuard Fireware OSto a version that resolves this vulnerability.Fixed in 12.11.5 - Upgrade
Upgrade
WatchGuard Fireware OSto a version that resolves this vulnerability.Fixed in 12.5.14 - Compensating control
Until patched, avoid using the Fireware OS certificate request command with any untrusted or specially crafted CLI input; restrict CLI access to authenticated privileged users only.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12026?
CVE-2025-12026 has been classified with a high severity rating due to its potential for arbitrary code execution.
How do I fix CVE-2025-12026?
To fix CVE-2025-12026, upgrade your WatchGuard Fireware OS to version 12.11.5 or later.
Who is affected by CVE-2025-12026?
CVE-2025-12026 affects authenticated privileged users of WatchGuard Fireware OS versions 12.0 to 12.11.4 and 12.5 to 12.5.13.
What can attackers do with CVE-2025-12026?
Attackers exploiting CVE-2025-12026 can execute arbitrary code on affected systems via specially crafted CLI commands.
When was CVE-2025-12026 disclosed?
CVE-2025-12026 was disclosed in 2025, highlighting its significance in the context of cybersecurity vulnerabilities.