CVE-2025-12195
- EPSS 0.12%
- Veröffentlicht 04.12.2025 21:43:57
- Zuletzt bearbeitet 08.12.2025 18:27:15
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to execute arbitrary code via specially crafted IPSec configuration CLI commands.This vulnerability affects Fireware OS 11.0 up to and i...
CVE-2025-12026
- EPSS 0.09%
- Veröffentlicht 04.12.2025 21:43:46
- Zuletzt bearbeitet 08.12.2025 18:27:15
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS’s certificate request command could allow an authenticated privileged user to execute arbitrary code via specially crafted CLI commands.This vulnerability affects Fireware OS 12.0 up to a...
CVE-2025-4106
- EPSS 0.06%
- Veröffentlicht 24.10.2025 21:32:30
- Zuletzt bearbeitet 27.10.2025 13:20:15
An authenticated admin user with access to both the management WebUI and command line interface on a Firebox can enable a diagnostic debug shell by uploading a platform and version-specific diagnostic package and executing a leftover diagnostic comma...
CVE-2025-9242
- EPSS 74.37%
- Veröffentlicht 17.09.2025 07:29:23
- Zuletzt bearbeitet 14.11.2025 02:00:02
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the Mobile User VPN with IKEv2 and the Branch Office VPN using IKEv2 when configured...
CVE-2025-6947
- EPSS 0.08%
- Veröffentlicht 15.09.2025 21:18:36
- Zuletzt bearbeitet 16.09.2025 12:49:16
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS allows Stored XSS via the SIP Proxy module. This vulnerability requires an authenticated administrator session to a lo...
CVE-2025-6999
- EPSS 0.26%
- Veröffentlicht 15.09.2025 21:17:51
- Zuletzt bearbeitet 16.09.2025 12:49:16
An HTTP Request Smuggling [CWE-444] vulnerability in the Authentication portal of WatchGuard Fireware OS allows a remote attacker to evade request parameter sanitation and perform a reflected self-Cross-Site Scripting (XSS) attack.This issue affects ...
CVE-2025-4805
- EPSS 0.08%
- Veröffentlicht 16.05.2025 20:13:47
- Zuletzt bearbeitet 19.05.2025 13:35:20
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS allows Stored XSS. This vulnerability requires an authenticated administrator session to a locally managed Firebox. Th...
CVE-2025-4804
- EPSS 0.08%
- Veröffentlicht 16.05.2025 20:12:44
- Zuletzt bearbeitet 19.05.2025 13:35:20
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS allows Stored XSS via the spamBlocker module. This vulnerability requires an authenticated administrator session to a ...
CVE-2025-1239
- EPSS 0.46%
- Veröffentlicht 14.02.2025 14:15:32
- Zuletzt bearbeitet 14.02.2025 14:15:32
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS allows Stored XSS via the Blocked Sites list. This vulnerability requires an authenticated administrator session to a ...
CVE-2025-1071
- EPSS 0.46%
- Veröffentlicht 14.02.2025 14:15:32
- Zuletzt bearbeitet 14.02.2025 14:15:32
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS allows Stored XSS via the spamBlocker module. This vulnerability requires an authenticated administrator session to a ...