WatchGuard Patches VPN PrivEsc & Firebox LDAP Injection
ID: 4cf503f8-a1b7-59c3-bdc9-7bafc6c07d66
STIX ID: report--4cf503f8-a1b7-59c3-bdc9-7bafc6c07d66
Feed Name: securityonline.info
WatchGuard published advisories for two security flaws: a local privilege escalation in the Windows Mobile VPN with IPSec MSI installer (NCPVE-2025-0626) that can allow a local user to execute commands as SYSTEM during install/update, and an LDAP Injection in Fireware OS (CVE-2026-1498, CVSS 7.0) that may permit remote unauthenticated attackers to retrieve sensitive LDAP data and potentially authenticate as an LDAP user with a known passphrase; administrators are urged to upgrade to the listed fixed Fireware and client versions immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
