CVE-2025-1547

Summary

A stack-based buffer overflow vulnerability [CWE-121] in WatchGuard Fireware OS's certificate request command could allow an authenticated privileged user to execute arbitrary code via specially crafted CLI commands.

Affected Software

VendorProductVersion RangeStatus
WatchGuardFireware OS12.0 <= 12.11.3affected
WatchGuardFireware OS12.0 < 12.5.13affected

Weaknesses

  • CWE-121: CWE-121

Workarounds

WatchGuard Firebox administrators should never expose management interfaces, including the command line interface, to untrusted networks. Follow WatchGuard's Firebox Remote Management Best Practices for additional guidance.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References