PT-2025-37990 · Watchguard · Fireware Os+1

Published

2025-09-16

·

Updated

2025-12-05

·

CVE-2025-6946

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions WatchGuard Fireware OS versions 12.0 through 12.11.2
Description A flaw exists in WatchGuard Fireware OS related to improper input handling during web page generation, potentially leading to Stored Cross-site Scripting (XSS). This issue is present within the IPS module and requires an authenticated administrator session to a locally managed Firebox to be exploited.
Recommendations Update to a version later than 12.11.2.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-6946

Affected Products

Fireware Os
Fireware