CVE-2025-13940#
WatchGuard Firebox Boot Time System Integrity Check Bypass
Summary #
An Expected Behavior Violation [CWE-440] vulnerability in WatchGuard Fireware OS may allow an attacker to bypass the Fireware OS boot time system integrity check and prevent the Firebox from shutting down in the event of a system integrity check failure. The on-demand system integrity check in the Fireware Web UI will correctly show a failed system integrity check message in the event of a failure.
Product status #
| Product | Affected | Not affected |
|---|---|---|
| Fireware OS | >= 2025.1, < 2025.1.3, >= 12.8.1, < 12.11.5 | >= 2025.1.3, >= 12.11.5 |
Weakness Type and Impact #
Exploitation Status #
WatchGuard is not aware of any exploitation of this vulnerability in the wild.
Solution #
Fireware OS 2025.1.3, Fireware OS 12.11.5
References #
Credits #
- Discovered internally by WatchGuardfinder