CVE-2025-4106
published 2025-10-24CVE-2025-4106: An authenticated admin user with access to both the management WebUI and command line interface on a Firebox can enable a diagnostic debug shell by uploading a…
PriorityP350high8.9CVSS 4.0
AVNACLATPPRHUINVCHVIHVAHSCHSIHSAHEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.30%
22.7th percentile
An authenticated admin user with access to both the management WebUI and command line interface on a Firebox can enable a diagnostic debug shell by uploading a platform and version-specific diagnostic package and executing a leftover diagnostic command.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| watchguard | fireware_os | >= 12.0 < 12.11.3 | 12.11.3 |
| watchguard | fireware_os | >= 12.0 < 12.5.13 | 12.5.13 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-23g2-f757-4428: An authenticated admin user with access to both the management WebUI and command line interface on a Firebox can enable a diagnostic debug shell by up
ghsa_unreviewed·2025-10-25
CVE-2025-4106 [HIGH] CWE-489 GHSA-23g2-f757-4428: An authenticated admin user with access to both the management WebUI and command line interface on a Firebox can enable a diagnostic debug shell by up
An authenticated admin user with access to both the management WebUI and command line interface on a Firebox can enable a diagnostic debug shell by uploading a platform and version-specific diagnostic package and executing a leftover diagnostic command.
This issue affects Fireware OS: from 12.0 before 12.11.2.
Citrix
Citrix Security Bulletin CTX206006
vendor_citrix·CVSS 4.6
CVE-2015-4106 [MEDIUM] Citrix Security Bulletin CTX206006
Citrix Security Bulletin CTX206006
CVE References: CVE-2015-4106, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX201145
vendor_citrix·CVSS 4.6
CVE-2015-4106 [MEDIUM] Citrix Security Bulletin CTX201145
Citrix Security Bulletin CTX201145
CVE References: CVE-2015-4106, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-10-24
Published