CVE-2025-13940
- EPSS 0.12%
- Veröffentlicht 04.12.2025 21:47:44
- Zuletzt bearbeitet 25.09.2026 23:10:00
An Expected Behavior Violation [CWE-440] vulnerability in WatchGuard Fireware OS may allow an attacker to bypass the Fireware OS boot time system integrity check and prevent the Firebox from shutting down in the event of a system integrity check fail...
CVE-2025-13939
- EPSS 0.19%
- Veröffentlicht 04.12.2025 21:47:37
- Zuletzt bearbeitet 25.09.2026 23:10:00
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Gateway Wireless Controller module) allows Stored XSS.
CVE-2025-13938
- EPSS 0.19%
- Veröffentlicht 04.12.2025 21:47:29
- Zuletzt bearbeitet 25.09.2026 23:10:00
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Autotask Technology Integration module) allows Stored XSS.
CVE-2025-13937
- EPSS 0.19%
- Veröffentlicht 04.12.2025 21:47:19
- Zuletzt bearbeitet 25.09.2026 23:10:00
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (ConnectWise Technology Integration module) allows Stored XSS.
CVE-2025-13936
- EPSS 0.19%
- Veröffentlicht 04.12.2025 21:45:51
- Zuletzt bearbeitet 25.09.2026 23:10:00
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Tigerpaw Technology Integration module) allows Stored XSS.
CVE-2025-12196
- EPSS 0.61%
- Veröffentlicht 04.12.2025 21:45:29
- Zuletzt bearbeitet 10.08.2026 16:19:13
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to execute arbitrary code via a specially crafted CLI command.
CVE-2025-12195
- EPSS 0.68%
- Veröffentlicht 04.12.2025 21:43:57
- Zuletzt bearbeitet 10.08.2026 16:19:13
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to execute arbitrary code via specially crafted IPSec configuration CLI commands.
CVE-2025-12026
- EPSS 0.43%
- Veröffentlicht 04.12.2025 21:43:46
- Zuletzt bearbeitet 10.08.2026 16:19:13
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS’s certificate request command could allow an authenticated privileged user to execute arbitrary code via specially crafted CLI commands.
CVE-2025-4106
- EPSS 0.31%
- Veröffentlicht 24.10.2025 21:32:30
- Zuletzt bearbeitet 08.08.2026 03:16:44
An authenticated admin user with access to both the management WebUI and command line interface on a Firebox can enable a diagnostic debug shell by uploading a platform and version-specific diagnostic package and executing a leftover diagnostic comma...
CVE-2025-9242
- EPSS 91.3%
- Veröffentlicht 17.09.2025 07:29:23
- Zuletzt bearbeitet 10.08.2026 19:59:12
An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv...