MEDIUM
WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in IPS Configuration
Published Dec 4, 2025
4.8
MEDIUMCVSS 4.0
EPSS 0.24%
Description
A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the IPS configuration. An authenticated remote attacker with administrator privileges could exploit this vulnerability to execute arbitrary JavaScript code in the Firebox management ninterface of another management user.
Affected products
-
- Version 12.0StatusaffectedConstraints<12.11.3
- Version 12.0StatusaffectedConstraints<12.5.13
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| WatchGuard | Fireware OS | unaffected |
|
Configuration 1
AND
- ≥ 12.0.0 · < 12.11.3
Running on/with
OR
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
Configuration 2
AND
- ≥ 12.5 · < 12.5.13
Running on/with
OR
- n/a
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Fireware OS 12.11.3, Fireware OS 12.5.13
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-201296 Advisory
- https://psirt.watchguard.com/CVE-2025-6946 vendor-advisory
- https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2025-00011 vendor-advisoryVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-201296 | Advisory | |
| https://psirt.watchguard.com/CVE-2025-6946 | vendor-advisory | |
| https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2025-00011 | vendor-advisoryVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner WatchGuard
Published Dec 4, 2025
Updated Aug 8, 2026
Reserved Jul 1, 2025
Link CVE-2025-6946
CISA Vulnrichment
Updated Dec 5, 2025
ENISA EUVD
EUVD-2025-201296 Assigner WatchGuard
Published Dec 4, 2025
Updated Aug 8, 2026
Exploited since n/a
Link EUVD-2025-201296