CVE-2025-13940
MEDIUMDescription
An Expected Behavior Violation [CWE-440] vulnerability in WatchGuard Fireware OS may allow an attacker to bypass the Fireware OS boot time system integrity check and prevent the Firebox from shutting down in the event of a system integrity check failure. The on-demand system integrity check in the Fireware Web UI will correctly show a failed system integrity check message in the event of a failure.This issue affects Fireware OS: from 12.8.1 through 12.11.4, from 2025.1 through 2025.1.2.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| watchguard | fireware |
| watchguard | firebox_t115-w |
| watchguard | firebox_t125 |
| watchguard | firebox_t125-w |
| watchguard | firebox_t145 |
| watchguard | firebox_t145-w |
| watchguard | firebox_t185 |
| watchguard | fireware |
| watchguard | firebox_m270 |
| watchguard | firebox_m290 |
| watchguard | firebox_m370 |
| watchguard | firebox_m390 |
| watchguard | firebox_m440 |
| watchguard | firebox_m4600 |
| watchguard | firebox_m470 |
| watchguard | firebox_m4800 |
| watchguard | firebox_m5600 |
| watchguard | firebox_m570 |
| watchguard | firebox_m5800 |
| watchguard | firebox_m590 |
| watchguard | firebox_m670 |
| watchguard | firebox_m690 |
| watchguard | firebox_nv5 |
| watchguard | firebox_t20 |
| watchguard | firebox_t25 |
| watchguard | firebox_t40 |
| watchguard | firebox_t45 |
| watchguard | firebox_t55 |
| watchguard | firebox_t70 |
| watchguard | firebox_t80 |
| watchguard | firebox_t85 |
| watchguard | fireboxcloud |
| watchguard | fireboxv |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2025-13940? +
How severe is CVE-2025-13940? +
What products are affected by CVE-2025-13940? +
How do I check if I'm vulnerable to CVE-2025-13940? +
Related Vulnerabilities
Apollo Router is a configurable, graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. …
In danny-avila/librechat version 0.7.9, there is an insecure API design issue in the 2-Factor Authentication (2FA) flow. The system allows …
Tuleap is an Open Source Suite to improve management of software developments and collaboration. A malicious user could exploit this …
An Expected Behavior Violation vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved …
A vulnerability in the DocugamiReader class of the run-llama/llama_index repository, up to version 0.12.28, involves the use of MD5 hashing …
Issue summary: The POLY1305 MAC (message authentication code) implementation contains a bug that might corrupt the internal state of applications …