Vulnerability Description
An Improper Input Validation vulnerability in WatchGuard Fireware OS allows an attacker with network access to manipulate the value of the HTTP Host header in requests sent to the Web UI. An attacker could exploit this vulnerability to redirect users to malicious websites, poison the web cache, or inject malicious JavaScript into responses sent by the Web UI.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Watchguard | Fireware | >= 12.0.0, < 12.11.1 |
| Watchguard | Firebox M270 | All versions |
| Watchguard | Firebox M290 | All versions |
| Watchguard | Firebox M370 | All versions |
| Watchguard | Firebox M390 | All versions |
| Watchguard | Firebox M440 | All versions |
| Watchguard | Firebox M4600 | All versions |
| Watchguard | Firebox M470 | All versions |
| Watchguard | Firebox M4800 | All versions |
| Watchguard | Firebox M5600 | All versions |
| Watchguard | Firebox M570 | All versions |
| Watchguard | Firebox M5800 | All versions |
| Watchguard | Firebox M590 | All versions |
| Watchguard | Firebox M670 | All versions |
| Watchguard | Firebox M690 | All versions |
| Watchguard | Firebox Nv5 | All versions |
| Watchguard | Firebox T20 | All versions |
| Watchguard | Firebox T25 | All versions |
| Watchguard | Firebox T40 | All versions |
| Watchguard | Firebox T45 | All versions |
Related Weaknesses (CWE)
References
- https://psirt.watchguard.com/CVE-2025-0178
- https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2025-00003Vendor Advisory
FAQ
What is CVE-2025-0178?
CVE-2025-0178 is a vulnerability with a CVSS score of 6.1 (MEDIUM). An Improper Input Validation vulnerability in WatchGuard Fireware OS allows an attacker with network access to manipulate the value of the HTTP Host header in requests sent to the Web UI. An attacker ...
How severe is CVE-2025-0178?
CVE-2025-0178 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-0178?
Check the references section above for vendor advisories and patch information. Affected products include: Watchguard Fireware, Watchguard Firebox M270, Watchguard Firebox M290, Watchguard Firebox M370, Watchguard Firebox M390.