This issue affects Fireware OS: from 12.0 before 12.11.2.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 27 Oct 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Watchguard
Watchguard fireware |
|
| Vendors & Products |
Watchguard
Watchguard fireware |
Mon, 27 Oct 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 24 Oct 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authenticated admin user with access to both the management WebUI and command line interface on a Firebox can enable a diagnostic debug shell by uploading a platform and version-specific diagnostic package and executing a leftover diagnostic command. This issue affects Fireware OS: from 12.0 before 12.11.2. | |
| Title | WatchGuard Firebox leftover debug code vulnerability | |
| Weaknesses | CWE-489 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: WatchGuard
Published:
Updated: 2026-02-26T16:57:06.433Z
Reserved: 2025-04-30T00:34:47.769Z
Link: CVE-2025-4106
Updated: 2025-10-27T13:14:55.931Z
Status : Deferred
Published: 2025-10-24T22:15:40.653
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-4106
No data.
OpenCVE Enrichment
Updated: 2025-10-27T22:10:28Z