CVE-2025-12196: WatchGuard Firebox Authenticated Out of Bounds Write in Management CLI Ping Command
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to execute arbitrary code via a specially crafted CLI command.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
If immediate patching is not possible, restrict access to the Fireware OS management CLI (e.g., only allow trusted admin IPs and accounts to access the CLI) to limit authenticated privileged users who could send specially crafted CLI commands.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12196?
CVE-2025-12196 is considered a high severity vulnerability due to its potential for allowing arbitrary code execution.
How do I fix CVE-2025-12196?
To mitigate CVE-2025-12196, upgrade WatchGuard Fireware OS to version 12.11.5 or later, or 12.5.14 and later.
Who is affected by CVE-2025-12196?
CVE-2025-12196 affects authenticated privileged users of WatchGuard Fireware OS versions from 12.0 to 12.11.4 and from 12.5 to 12.5.13.
What type of vulnerability is CVE-2025-12196?
CVE-2025-12196 is an Out-of-bounds Write vulnerability which can lead to unauthorized code execution.
What are the implications of CVE-2025-12196 for my network security?
If exploited, CVE-2025-12196 could allow attackers to gain control over affected devices, compromising network security.