CVE-2025-4106: WatchGuard Fireware OS

High severity, CVSS 8.9. EPSS: 0.3% chance of exploitation in the next 30 days.

An authenticated admin user with access to both the management WebUI and command line interface on a Firebox can enable a diagnostic debug shell by uploading a platform and version-specific diagnostic package and executing a leftover diagnostic command.

Affected products

  • WatchGuard Fireware OS: from 12.0, before 12.11.3 (fixed in 12.11.3); from 12.0, before 12.5.13 (fixed in 12.5.13)

Published 2025-10-24. Last modified 2026-10-08.