CVE-2025-1239: WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Blocked Sites List
A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the Blocked Sites list. An authenticated remote attacker with administrator privileges could exploit this vulnerability to execute arbitrary JavaScript code in the Firebox management interface of another management user.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WatchGuard Firebox Fireware OSto a version that resolves this vulnerability.Fixed in 12.11.1 - Upgrade
Upgrade
WatchGuard Firebox Fireware OSto a version that resolves this vulnerability.Fixed in 12.5.13
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1239?
CVE-2025-1239 is classified as a stored Cross-site Scripting (XSS) vulnerability with high severity.
How do I fix CVE-2025-1239?
To mitigate CVE-2025-1239, ensure you upgrade to a patched version of WatchGuard Fireware OS beyond the affected versions listed.
What versions of WatchGuard Fireware OS are affected by CVE-2025-1239?
CVE-2025-1239 affects WatchGuard Fireware OS versions from 12.0 up to 12.11 and 12.5.12.
What causes the vulnerability CVE-2025-1239?
CVE-2025-1239 is caused by improper neutralization of input during web page generation allowing for stored XSS.
Who needs to be concerned about CVE-2025-1239?
Authenticated administrators managing a locally managed Firebox should be particularly concerned about CVE-2025-1239.