A critical vulnerability (CVE-2025-59396, CVSS 9.8) has been found in WatchGuard Firebox devices, allowing remote attackers to gain unauthorized administrative access via SSH using default credentials. The flaw is due to an insecure default configuration that leaves SSH access enabled on port 4118, using the built-in admin readwrite credentials. This misconfiguration exposes Firebox appliances to exploitation, enabling attackers to easily gain root-level access to the device. Once attackers access the device, they can retrieve sensitive data, such as ARP tables, network configurations, and user accounts. They can also modify firewall rules, disable security policies, and perform lateral movement within the internal network. This gives them full control over the firewall, which acts as the central security gateway for many enterprise and SMB networks. The impact can include data theft, service disruption, or further attacks within the network. The vulnerability is particularly dangerous due to its predictable port and publicly known default credentials, making it a prime target for mass scanning and exploitation campaigns. Attackers can exploit exposed Firebox devices on the internet, potentially compromising large numbers of devices that have not been properly secured. To mitigate the risk, administrators should immediately disable SSH on port 4118, change the default credentials, and ensure management interfaces are restricted to trusted networks only. WatchGuard users are strongly encouraged to review their configurations and apply necessary security updates to prevent exploitation.
Security researchers have uncovered a large-scale cyber campaign in which threat actors combined exploited Fortinet weaknesses, AI-assisted tooling, and custom command-and-control ...
Cybersecurity researchers have uncovered a new Android spyware strain known as Asin that appears to be targeting Arabic-speaking individuals through a series of deceptive mobile ap...
A recently disclosed supply chain vulnerability in Anthropic’s Claude Code GitHub Actions integration exposed numerous repositories to potential compromise through a single malic...