CVE-2025-1549: WatchGuard Mobile VPN With SSL Client
Medium severity, CVSS 6.3. EPSS: 0.2% chance of exploitation in the next 30 days.
A local privilege escalation vulnerability in the WatchGuard Mobile VPN with SSL client on Windows enables a local user to execute arbitrary commands with elevated privileges on the Windows system. This vulnerability is an additional unmitigated attack path for CVE-2024-4944. This vulnerability is resolved in the Mobile VPN with SSL client for Windows version 12.11.5
Affected products
- WatchGuard Mobile VPN With SSL Client: from 12.0, before 12.11.3 (fixed in 12.11.3)
Published 2025-10-29. Last modified 2026-10-08.