CVE-2025-12195: WatchGuard Firebox Authenticated Out of Bounds Write in Management CLI IPSec Configuration
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to execute arbitrary code via specially crafted IPSec configuration CLI commands.This vulnerability affects Fireware OS 11.0 up to and including 11.12.4+541730, 12.0 up to and including 12.11.4, 12.5 up to and including 12.5.13, and 2025.1 up to and including 2025.1.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12195?
CVE-2025-12195 is categorized as a high severity vulnerability due to its potential to allow arbitrary code execution.
How do I fix CVE-2025-12195?
To fix CVE-2025-12195, upgrade to Fireware OS version 12.11.5 or later as recommended by the vendor.
Who is affected by CVE-2025-12195?
CVE-2025-12195 affects authenticated privileged users of WatchGuard Fireware OS versions 11.0 to 12.11.4 and some later versions.
What type of vulnerability is CVE-2025-12195?
CVE-2025-12195 is an Out-of-bounds Write vulnerability that occurs specifically in the CLI of WatchGuard Fireware OS.
Can CVE-2025-12195 be exploited remotely?
CVE-2025-12195 requires authenticated access, so it cannot be exploited remotely without privileged user credentials.