CVE-2025-6946: WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in IPS Configuration
A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the IPS configuration. An authenticated remote attacker with administrator privileges could exploit this vulnerability to execute arbitrary JavaScript code in the Firebox management ninterface of another management user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6946?
CVE-2025-6946 is classified as a high severity vulnerability due to its potential for stored Cross-site Scripting (XSS).
How do I fix CVE-2025-6946?
To fix CVE-2025-6946, update your WatchGuard Fireware OS or Firebox to a version later than 12.11.2 if you are running any version from 12.0 to 12.11.2.
Who is affected by CVE-2025-6946?
CVE-2025-6946 affects users with an authenticated administrator session on locally managed WatchGuard Firebox appliances running specified versions of Fireware OS.
What type of vulnerability is CVE-2025-6946?
CVE-2025-6946 is an Improper Neutralization of Input During Web Page Generation, specifically a stored XSS vulnerability.
What is the impact of CVE-2025-6946 on my system?
CVE-2025-6946 can allow an attacker to execute malicious scripts in the context of an authenticated administrator, potentially compromising the Firebox system.