📦 Fireware

by Watchguard

🔍 What is Fireware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-14733

CRITICAL CVSS 9.8 Dec 19, 2025

A critical out-of-bounds write vulnerability in WatchGuard Fireware OS allows remote unauthenticated attackers to execute arbitrary code on affected systems. This affects Mobile User VPN and Branch Of...

CVE-2025-9242

CRITICAL CVSS 9.8 Sep 17, 2025

An out-of-bounds write vulnerability in WatchGuard Fireware OS allows remote unauthenticated attackers to execute arbitrary code on affected systems. This affects Mobile User VPN and Branch Office VPN...

CVE-2022-25361

CRITICAL CVSS 9.1 Jun 7, 2022

CVE-2022-25361 allows unauthenticated remote attackers to delete arbitrary files from specific directories on WatchGuard Firebox and XTM appliances. This affects Fireware OS versions before 12.7.2_U2,...

CVE-2022-26318

CRITICAL CVSS 9.8 Mar 4, 2022

CVE-2022-26318 is a critical remote code execution vulnerability affecting WatchGuard Firebox and XTM firewall appliances. Unauthenticated attackers can exploit this vulnerability to execute arbitrary...

CVE-2025-1545

HIGH CVSS 7.5 Dec 4, 2025

An XPath injection vulnerability in WatchGuard Fireware OS allows remote unauthenticated attackers to extract sensitive configuration data from Firebox devices. This affects systems with authenticatio...

CVE-2025-1547

HIGH CVSS 7.2 Dec 4, 2025

A stack-based buffer overflow vulnerability in WatchGuard Fireware OS allows authenticated privileged users to execute arbitrary code via specially crafted CLI commands. This affects Fireware OS versi...

CVE-2025-12196

HIGH CVSS 7.2 Dec 4, 2025

An authenticated privileged user can exploit an out-of-bounds write vulnerability in WatchGuard Fireware OS's CLI via a specially crafted command to execute arbitrary code. This affects Fireware OS ve...

CVE-2025-12026

HIGH CVSS 7.2 Dec 4, 2025

An authenticated privileged user can execute arbitrary code on WatchGuard Fireware OS devices by exploiting an out-of-bounds write vulnerability in the certificate request command. This affects Firewa...

CVE-2025-12195

HIGH CVSS 7.2 Dec 4, 2025

An authenticated privileged user can execute arbitrary code on WatchGuard Fireware OS devices by sending specially crafted IPSec configuration commands through the CLI. This out-of-bounds write vulner...

CVE-2025-11838

HIGH CVSS 7.5 Dec 4, 2025

A memory corruption vulnerability in WatchGuard Fireware OS allows unauthenticated attackers to trigger Denial of Service (DoS) conditions in Mobile User VPN and Branch Office VPN when configured with...

CVE-2022-25291

HIGH CVSS 8.8 Feb 24, 2022

An integer overflow vulnerability in WatchGuard Firebox and XTM appliances allows authenticated remote attackers to trigger a heap-based buffer overflow via malicious firmware upgrade images, potentia...

CVE-2022-25293

HIGH CVSS 8.8 Feb 24, 2022

CVE-2022-25293 is a stack-based buffer overflow vulnerability in systemd on WatchGuard Firebox and XTM appliances, allowing authenticated remote attackers to potentially execute arbitrary code by init...

CVE-2022-25360

HIGH CVSS 8.8 Feb 24, 2022

CVE-2022-25360 allows authenticated remote attackers with unprivileged credentials to upload files to arbitrary locations on WatchGuard Firebox and XTM appliances. This vulnerability affects Fireware ...

CVE-2025-6946

MEDIUM CVSS 4.8 Dec 4, 2025

This stored cross-site scripting (XSS) vulnerability in WatchGuard Fireware OS allows authenticated administrators to inject malicious scripts via the IPS module. Attackers could execute arbitrary Jav...

CVE-2025-13939

MEDIUM CVSS 6.1 Dec 4, 2025

This CVE describes a stored cross-site scripting (XSS) vulnerability in WatchGuard Fireware OS's Gateway Wireless Controller module. Attackers can inject malicious scripts that execute when administra...

CVE-2025-13940

MEDIUM CVSS 5.5 Dec 4, 2025

This vulnerability in WatchGuard Fireware OS allows attackers to bypass the boot-time system integrity check and prevent the Firebox from shutting down when integrity checks fail. It affects Fireware ...

CVE-2025-13936

MEDIUM CVSS 6.1 Dec 4, 2025

A stored cross-site scripting (XSS) vulnerability in WatchGuard Fireware OS's Tigerpaw Technology Integration module allows attackers to inject malicious scripts into web pages. When users view these ...

CVE-2025-13937

MEDIUM CVSS 6.1 Dec 4, 2025

A stored cross-site scripting (XSS) vulnerability in WatchGuard Fireware OS allows attackers to inject malicious scripts into web pages generated by the ConnectWise Technology Integration module. When...

CVE-2025-13938

MEDIUM CVSS 6.1 Dec 4, 2025

This stored cross-site scripting (XSS) vulnerability in WatchGuard Fireware OS allows attackers to inject malicious scripts into web pages generated by the Autotask Technology Integration module. When...