216.73.217.22

CVE-2025-4106

· Published 24/10/2025 22:15 · Modified 24/10/2025 22:15

Labels: CVE-2025-4106 2025-10-245d1c2695-1a31-4499-88ae-e847036fd7e3CVE-2025-4106CWE-489

Essential information

Published
24/10/2025 22:15
Modified
24/10/2025 22:15
Author
Creator
CVSS
8.9 HIGH (v3) 8.9 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

An authenticated admin user with access to both the management WebUI and command line interface on a Firebox can enable a diagnostic debug shell by uploading a platform and version-specific diagnostic package and executing a leftover diagnostic command. This issue affects Fireware OS: from 12.0 before 12.11.2.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
5d1c2695-1a31-4499-88ae-e847036fd7e3
NVD
View on NVD

Affected products (CPE)

ProductCPE
watchguard / fireware os cpe:2.3:o:watchguard:fireware_os:<12.11.2:*:*:*:*:*:*:*

References