CVE-2025-1547

WatchGuard Firebox Authenticated Stack Overflow in Certificate Request Command

High 7.5 CVSS v4.0 › Published 2025-12-04Updated 2026-08-10

Summary #

A stack-based buffer overflow vulnerability [CWE-121] in WatchGuard Fireware OS's certificate request command could allow an authenticated privileged user to execute arbitrary code via specially crafted CLI commands.

Product status #

ProductAffectedNot affected
Fireware OS
Default >= 12.0, <= 12.11.3> 12.11.3
T15/T35 >= 12.0, < 12.5.13>= 12.5.13

Weakness Type and Impact #

Solution #

Fireware OS 12.11.3, Fireware OS 12.5.13

Workaround #

WatchGuard Firebox administrators should never expose management interfaces, including the command line interface, to untrusted networks. Follow WatchGuard's Firebox Remote Management Best Practices for additional guidance.

References #

Credits #

  • Cody Sixteenfinder