
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-12195 is an Out-of-bounds Write vulnerability (CWE-787) in WatchGuard Fireware OS's command-line interface (CLI) that allows an authenticated privileged user to execute arbitrary code via specially crafted IPSec configuration CLI commands. The vulnerability was published on December 4, 2025, with a patch advisory released by WatchGuard on December 10, 2025. Affected versions include Fireware OS 11.0 through 11.12.4+541730, 12.0 through 12.11.4, 12.5 through 12.5.13, and 2025.1 through 2025.1.2. It carries a CVSS v3.1 base score of 7.2 (High) and a CVSS v4.0 base score of 8.6 (High) (WatchGuard Advisory, Red Hat CVE).
The root cause is an Out-of-bounds Write (CWE-787) in the Fireware OS CLI's handling of IPSec configuration commands. When an authenticated administrator submits specially crafted IPSec configuration parameters via the CLI, the OS fails to properly validate input boundaries, resulting in a memory write beyond the allocated buffer. Exploitation requires network access and high-privilege (administrative) credentials, with no user interaction needed. No public proof-of-concept or detailed technical write-up has been identified at this time (WatchGuard Advisory, Red Hat CVE).
Successful exploitation could allow an authenticated administrator to execute arbitrary code on the affected WatchGuard Firewall appliance, resulting in high confidentiality, integrity, and availability impact. An attacker with administrative access could gain full control of the firewall infrastructure, potentially creating backdoors, modifying security configurations, or disrupting network protection for all traffic passing through the device. Given the role of these appliances as network security gatekeepers, compromise could facilitate lateral movement into protected network segments (WatchGuard Advisory, SecurityOnline).
There is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation as of the time of reporting. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.064%, indicating a low probability of exploitation in the near term. Exploitation requires authenticated administrative access, which significantly limits the attack surface (WatchGuard Advisory, Red Hat CVE).
WatchGuard has released patched versions addressing this vulnerability: Fireware OS 12.5.14 or later (for the 12.5.x branch), 12.11.5 or later (for the 12.x branch), and 2025.1.3 or later (for the 2025.1 branch). Administrators should update to the latest available Fireware OS version immediately. As interim mitigations, restrict CLI administrative access to trusted management networks only, implement strong multi-factor authentication for administrative accounts, and monitor and log all administrative CLI activity for anomalous IPSec configuration commands (WatchGuard Advisory).
Security news outlets including SecurityOnline, CyberSecurityNews, GBHackers, and CyberNoz covered the vulnerability alongside related WatchGuard Firebox flaws, highlighting risks of VPN denial-of-service and remote code execution via IKEv2 memory corruption. The Hacker News included the vulnerability in its weekly recap covering notable December 2025 security disclosures. Community discussion on Infosec.exchange and CIRCL's vulnerability lookup service noted the advisory shortly after publication. Overall sentiment reflects moderate concern given the administrative privilege requirement, with no reports of active exploitation (SecurityOnline, CyberSecurityNews, GBHackers).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."