CVE-2025-12195
WatchGuard Firebox vulnerability analysis and mitigation

Overview

CVE-2025-12195 is an Out-of-bounds Write vulnerability (CWE-787) in WatchGuard Fireware OS's command-line interface (CLI) that allows an authenticated privileged user to execute arbitrary code via specially crafted IPSec configuration CLI commands. The vulnerability was published on December 4, 2025, with a patch advisory released by WatchGuard on December 10, 2025. Affected versions include Fireware OS 11.0 through 11.12.4+541730, 12.0 through 12.11.4, 12.5 through 12.5.13, and 2025.1 through 2025.1.2. It carries a CVSS v3.1 base score of 7.2 (High) and a CVSS v4.0 base score of 8.6 (High) (WatchGuard Advisory, Red Hat CVE).

Technical details

The root cause is an Out-of-bounds Write (CWE-787) in the Fireware OS CLI's handling of IPSec configuration commands. When an authenticated administrator submits specially crafted IPSec configuration parameters via the CLI, the OS fails to properly validate input boundaries, resulting in a memory write beyond the allocated buffer. Exploitation requires network access and high-privilege (administrative) credentials, with no user interaction needed. No public proof-of-concept or detailed technical write-up has been identified at this time (WatchGuard Advisory, Red Hat CVE).

Impact

Successful exploitation could allow an authenticated administrator to execute arbitrary code on the affected WatchGuard Firewall appliance, resulting in high confidentiality, integrity, and availability impact. An attacker with administrative access could gain full control of the firewall infrastructure, potentially creating backdoors, modifying security configurations, or disrupting network protection for all traffic passing through the device. Given the role of these appliances as network security gatekeepers, compromise could facilitate lateral movement into protected network segments (WatchGuard Advisory, SecurityOnline).

Exploitability

There is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation as of the time of reporting. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.064%, indicating a low probability of exploitation in the near term. Exploitation requires authenticated administrative access, which significantly limits the attack surface (WatchGuard Advisory, Red Hat CVE).

Mitigation and workarounds

WatchGuard has released patched versions addressing this vulnerability: Fireware OS 12.5.14 or later (for the 12.5.x branch), 12.11.5 or later (for the 12.x branch), and 2025.1.3 or later (for the 2025.1 branch). Administrators should update to the latest available Fireware OS version immediately. As interim mitigations, restrict CLI administrative access to trusted management networks only, implement strong multi-factor authentication for administrative accounts, and monitor and log all administrative CLI activity for anomalous IPSec configuration commands (WatchGuard Advisory).

Community reactions

Security news outlets including SecurityOnline, CyberSecurityNews, GBHackers, and CyberNoz covered the vulnerability alongside related WatchGuard Firebox flaws, highlighting risks of VPN denial-of-service and remote code execution via IKEv2 memory corruption. The Hacker News included the vulnerability in its weekly recap covering notable December 2025 security disclosures. Community discussion on Infosec.exchange and CIRCL's vulnerability lookup service noted the advisory shortly after publication. Overall sentiment reflects moderate concern given the administrative privilege requirement, with no reports of active exploitation (SecurityOnline, CyberSecurityNews, GBHackers).

Additional resources


SourceThis report was generated using AI

Related WatchGuard Firebox vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-13722HIGH8.6
  • WatchGuard Firebox logoWatchGuard Firebox
  • cpe:2.3:o:watchguard:fireware
NoYesJul 03, 2026
CVE-2026-13384HIGH8.6
  • WatchGuard Firebox logoWatchGuard Firebox
  • cpe:2.3:o:watchguard:fireware
NoYesJul 03, 2026
CVE-2026-13383HIGH8.6
  • WatchGuard Firebox logoWatchGuard Firebox
  • cpe:2.3:o:watchguard:fireware
NoYesJul 03, 2026
CVE-2026-8247HIGH7.7
  • WatchGuard Firebox logoWatchGuard Firebox
  • cpe:2.3:o:watchguard:fireware
NoYesJul 03, 2026
CVE-2026-13728MEDIUM5.9
  • WatchGuard Firebox logoWatchGuard Firebox
  • cpe:2.3:o:watchguard:fireware
NoYesJul 03, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management