CVE-2025-4106

WatchGuard Firebox leftover debug code vulnerability

High 8.9 CVSS v4.0 › Published 2025-10-24Updated 2026-08-08

Summary #

An authenticated admin user with access to both the management WebUI and command line interface on a Firebox can enable a diagnostic debug shell by uploading a platform and version-specific diagnostic package and executing a leftover diagnostic command.

Product status #

ProductAffectedNot affected
Fireware OS
Default >= 12.0, < 12.11.3>= 12.11.3
T15/T35 >= 12.0, < 12.5.13>= 12.5.13

Weakness Type and Impact #

Exploitation Status #

WatchGuard is not aware of any exploitation of this vulnerability in the wild.

Solution #

Fireware OS 12.11.3, Fireware OS 12.5.13

References #