CVE Vulnerabilities

CVE-2025-4106

Active Debug Code

Published: Oct 24, 2025 | Modified: Oct 24, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An authenticated admin user with access to both the management WebUI and command line interface on a Firebox can enable a diagnostic debug shell by uploading a platform and version-specific diagnostic package and executing a leftover diagnostic command.

This issue affects Fireware OS: from 12.0 before 12.11.2.

Weakness

The product is released with debugging code still enabled or active.

Potential Mitigations

References