CVE-2025-6946
MEDIUMDescription
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS allows Stored XSS via the IPS module. This vulnerability requires an authenticated administrator session to a locally managed Firebox. This issue affects Firebox: from 12.0 through 12.11.2.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| watchguard | fireware |
| watchguard | firebox_m270 |
| watchguard | firebox_m290 |
| watchguard | firebox_m370 |
| watchguard | firebox_m390 |
| watchguard | firebox_m440 |
| watchguard | firebox_m4600 |
| watchguard | firebox_m470 |
| watchguard | firebox_m4800 |
| watchguard | firebox_m5600 |
| watchguard | firebox_m570 |
| watchguard | firebox_m5800 |
| watchguard | firebox_m590 |
| watchguard | firebox_m670 |
| watchguard | firebox_m690 |
| watchguard | firebox_nv5 |
| watchguard | firebox_t20 |
| watchguard | firebox_t25 |
| watchguard | firebox_t40 |
| watchguard | firebox_t45 |
| watchguard | firebox_t55 |
| watchguard | firebox_t70 |
| watchguard | firebox_t80 |
| watchguard | firebox_t85 |
| watchguard | fireboxcloud |
| watchguard | fireboxv |
| watchguard | fireware |
| watchguard | firebox_t15 |
| watchguard | firebox_t35 |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2025-6946? +
How severe is CVE-2025-6946? +
What products are affected by CVE-2025-6946? +
How do I check if I'm vulnerable to CVE-2025-6946? +
Related Vulnerabilities
WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vulnerability allows …
Reflected Cross-Site Scripting (XSS) vulnerability in Navigate Content Management System. The vulnerability is present in the '/blog' endpoint because user …
Cross-Site Scripting (XSS) vulnerability reflected in Semantic MediaWiki. This vulnerability allows an attacker to execute JavaScript code in the victim's …
Bludit CMS prior to commit 6732dde contains a reflected cross-site scripting vulnerability in the search plugin that allows unauthenticated attackers …
mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the admin dashboard's Autodiscover …
mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the mailcow web interface …