CVE-2025-0178

MEDIUM

WatchGuard Fireware OS <12.11 - XSS

Title source: llm
STIX 2.1

Description

Improper Input Validation vulnerability in WatchGuard Fireware OS allows an attacker to manipulate the value of the HTTP Host header in requests sent to the Web UI. An attacker could exploit this vulnerability to redirect users to malicious websites, poison the web cache, or inject malicious JavaScript into responses sent by the Web UI. This issue affects Fireware OS: from 12.0 up to and including 12.11.

References (1)

Core 1

Scores

CVSS v3 6.1
EPSS 0.0022
EPSS Percentile 11.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (1)
watchguard/fireware 12.5 - 12.5.13
Published Feb 14, 2025
Tracked Since Feb 18, 2026