CVE-2025-1547

HIGH EPSS 14.5%
Published Dec 4, 20256mo ago · Modified Jun 17, 20261w ago
7.5 CVSS 4.0
High
Find Similar
Published Dec 4, 2025 6mo ago
Last Modified Jun 17, 2026 1w ago

Description

A stack-based buffer overflow vulnerability [CWE-121] in WatchGuard Fireware OS's certificate request command could allow an authenticated privileged user to execute arbitrary code via specially crafted CLI commands.This issue affects Fireware OS: from 12.0 through 12.5.12+701324, from 12.6 through 12.11.2.

CVSS Details

Base Score
7.5
Exploitability
Impact
Vector string
CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Attack Vector Network
Attack Complexity High
Privileges Required High
User Interaction None
Scope X

Threat Intelligence

EPSS Exploit Probability
14.5% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available

Weaknesses 1

CWE-121

Affected Products 29

VendorProductVersionRange
watchguardfireware*≥12.0.0  –  <12.11.3
watchguardfirebox_m270*any
watchguardfirebox_m290*any
watchguardfirebox_m370*any
watchguardfirebox_m390*any
watchguardfirebox_m440*any
watchguardfirebox_m4600*any
watchguardfirebox_m470*any
watchguardfirebox_m4800*any
watchguardfirebox_m5600*any
watchguardfirebox_m570*any
watchguardfirebox_m5800*any
watchguardfirebox_m590*any
watchguardfirebox_m670*any
watchguardfirebox_m690*any
watchguardfirebox_nv5*any
watchguardfirebox_t20*any
watchguardfirebox_t25*any
watchguardfirebox_t40*any
watchguardfirebox_t45*any
watchguardfirebox_t55*any
watchguardfirebox_t70*any
watchguardfirebox_t80*any
watchguardfirebox_t85*any
watchguardfireboxcloud*any
watchguardfireboxv*any
watchguardfireware*≥12.5  –  <12.5.13
watchguardfirebox_t15*any
watchguardfirebox_t35*any

References 1

  • watchguard.com https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2025-00013
    Vendor Advisory

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.