WatchGuard Fireware OS是美国WatchGuard公司的一个在 Firebox 上运行的软件。 WatchGuard Fireware OS 11.11版本至11.12.4+541730版本和12.0版本至12.11.4版本和12.5版本至12.5.13版本和2025.1版本至2025.1.2版本存在安全漏洞,该漏洞源于XPath注入,可能导致敏感信息泄露。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| WatchGuard | Fireware OS | 2025.1< 2025.1.3 |
affected |
12.0< 12.11.5 |
affected | ||
11.11≤ 11.12.4+541730 |
affected | ||
12.0< 12.5.14 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| WatchGuard | Fireware OS | 2025.1 ~ 2025.1.3 | - |
|
| WatchGuard | Fireware OS | 12.0 ~ 12.5.14 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-11838 | 8.7 HIGH | WatchGuard Firebox iked Memory Corruption Vulnerability |
| CVE-2025-12196 | 8.6 HIGH | WatchGuard Firebox Authenticated Out of Bounds Write in Management CLI Ping Command |
| CVE-2025-12195 | 8.6 HIGH | WatchGuard Firebox Authenticated Out of Bounds Write in Management CLI IPSec Configuration |
| CVE-2025-12026 | 8.6 HIGH | WatchGuard Firebox Authenticated Out of Bounds Write in certd |
| CVE-2025-1547 | 7.5 HIGH | WatchGuard Firebox Authenticated Stack Overflow in Certificate Request Command |
| CVE-2025-13940 | 6.7 MEDIUM | WatchGuard Firebox Boot Time System Integrity Check Bypass |
| CVE-2025-1910 | 6.3 MEDIUM | WatchGuard Mobile VPN with SSL Local Privilege Escalation via Update Package |
| CVE-2025-6946 | 4.8 MEDIUM | WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in IPS Configuration |
| CVE-2025-13937 | 4.8 MEDIUM | WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in ConnectWise Technolo |
| CVE-2025-13936 | 4.8 MEDIUM | WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Tigerpaw Technology |
| CVE-2025-13939 | 4.8 MEDIUM | WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Gateway Wireless Con |
| CVE-2025-13938 | 4.8 MEDIUM | WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Autotask Technology |
No comments yet