216.73.216.133

CVE-2025-6999

· Published 15/09/2025 22:15 · Modified 16/09/2025 12:49

Labels: CVE-2025-6999 2025-09-155d1c2695-1a31-4499-88ae-e847036fd7e3CVE-2025-6999CWE-444

Essential information

Published
15/09/2025 22:15
Modified
16/09/2025 12:49
Author
Creator
CVSS
6.9 MEDIUM (v3) 6.9 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

An HTTP Request Smuggling [CWE-444] vulnerability in the Authentication portal of WatchGuard Fireware OS allows a remote attacker to evade request parameter sanitation and perform a reflected self-Cross-Site Scripting (XSS) attack.This issue affects Fireware OS: from 12.0 through 12.11.2.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
5d1c2695-1a31-4499-88ae-e847036fd7e3
NVD
View on NVD

Affected products (CPE)

ProductCPE
watchguard / fireware os cpe:2.3:a:watchguard:fireware_os:12.0-12.11.2:*:*:*:*:*:*:*

References