nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-13940 CVE-2025-13940
MEDIUM
WatchGuard Firebox Boot Time System Integrity Check Bypass
Record summary
CVE-2025-13940 has a selected CVSS score of 6.7 (medium).
Description
An Expected Behavior Violation [CWE-440] vulnerability in WatchGuard Fireware OS may allow an attacker to bypass the Fireware OS boot time system integrity check and prevent the Firebox from shutting down in the event of a system integrity check failure. The on-demand system integrity check in the Fireware Web UI will correctly show a failed system integrity check message in the event of a failure.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 5, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Fireware OSBrowse WatchGuard / Fireware OSDefault status: unaffected | CVE List | 2025.1 to < 2025.1.3 | affected |
| 12.8.1 to < 12.11.5 | affected |
References
3psirt.watchguard.comVendor advisory
https://psirt.watchguard.com/CVE-2025-13940 watchguard.comVendor advisory
https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2025-00026