CVE-2025-1071: WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in spamBlocker Module
A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the spamBlocker module. An authenticated remote attacker with administrator privileges could exploit this vulnerability to execute arbitrary JavaScript code in the Firebox management interface of another management user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1071?
The severity of CVE-2025-1071 is classified as high due to the potential for Stored XSS in the WatchGuard Fireware OS.
How do I fix CVE-2025-1071?
To fix CVE-2025-1071, it is recommended to update WatchGuard Fireware OS to a version that addresses this vulnerability.
What software is affected by CVE-2025-1071?
CVE-2025-1071 affects WatchGuard Fireware OS versions from 12.0 to 12.5.12 and 12.6.
What type of vulnerability is CVE-2025-1071?
CVE-2025-1071 is an Improper Neutralization of Input During Web Page Generation vulnerability that leads to Stored XSS.
Who is affected by CVE-2025-1071?
Only authenticated administrators using a locally managed Firebox are affected by CVE-2025-1071.