Skip to finding
important · Edge — VPN

A malicious BOVPN over TLS server can execute commands as root on a connecting Firebox.

Affects

WatchGuard Firebox network-security appliances running Fireware OS and configured as BOVPN over TLS clients.

The Firebox must already be configured to connect to the attacker-controlled server; improper certificate validation and code injection then turn server-supplied configuration into root commands.

Detail and 2 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Wednesday, September 30, 2026