Vulnerability Description
Improper Input Validation vulnerability in WatchGuard Fireware OS allows an attacker to manipulate the value of the HTTP Host header in requests sent to the Web UI. An attacker could exploit this vulnerability to redirect users to malicious websites, poison the web cache, or inject malicious JavaScript into responses sent by the Web UI. This issue affects Fireware OS: from 12.0 up to and including 12.11.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Watchguard | Fireware | >= 12.5, < 12.5.13 |
| Watchguard | Firebox T15 | All versions |
| Watchguard | Firebox T35 | All versions |
| Watchguard | Firebox M270 | All versions |
| Watchguard | Firebox M290 | All versions |
| Watchguard | Firebox M370 | All versions |
| Watchguard | Firebox M390 | All versions |
| Watchguard | Firebox M440 | All versions |
| Watchguard | Firebox M4600 | All versions |
| Watchguard | Firebox M470 | All versions |
| Watchguard | Firebox M4800 | All versions |
| Watchguard | Firebox M5600 | All versions |
| Watchguard | Firebox M570 | All versions |
| Watchguard | Firebox M5800 | All versions |
| Watchguard | Firebox M590 | All versions |
| Watchguard | Firebox M670 | All versions |
| Watchguard | Firebox M690 | All versions |
| Watchguard | Firebox Nv5 | All versions |
| Watchguard | Firebox T20 | All versions |
| Watchguard | Firebox T25 | All versions |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2025-0178?
CVE-2025-0178 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Improper Input Validation vulnerability in WatchGuard Fireware OS allows an attacker to manipulate the value of the HTTP Host header in requests sent to the Web UI. An attacker could exploit this vuln...
How severe is CVE-2025-0178?
CVE-2025-0178 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-0178?
Check the references section above for vendor advisories and patch information. Affected products include: Watchguard Fireware, Watchguard Firebox T15, Watchguard Firebox T35, Watchguard Firebox M270, Watchguard Firebox M290.