Vulnerability Description
A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the IPS configuration. An authenticated remote attacker with administrator privileges could exploit this vulnerability to execute arbitrary JavaScript code in the Firebox management ninterface of another management user.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Watchguard | Fireware | >= 12.0.0, < 12.11.3 |
| Watchguard | Firebox M270 | - |
| Watchguard | Firebox M290 | - |
| Watchguard | Firebox M370 | - |
| Watchguard | Firebox M390 | - |
| Watchguard | Firebox M440 | - |
| Watchguard | Firebox M4600 | - |
| Watchguard | Firebox M470 | - |
| Watchguard | Firebox M4800 | - |
| Watchguard | Firebox M5600 | - |
| Watchguard | Firebox M570 | - |
| Watchguard | Firebox M5800 | - |
| Watchguard | Firebox M590 | - |
| Watchguard | Firebox M670 | - |
| Watchguard | Firebox M690 | - |
| Watchguard | Firebox Nv5 | - |
| Watchguard | Firebox T20 | - |
| Watchguard | Firebox T25 | - |
| Watchguard | Firebox T40 | - |
| Watchguard | Firebox T45 | - |
Related Weaknesses (CWE)
References
- https://psirt.watchguard.com/CVE-2025-6946
- https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2025-00011Vendor Advisory
FAQ
What is CVE-2025-6946?
CVE-2025-6946 is a vulnerability with a CVSS score of 4.8 (MEDIUM). A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the IPS configuration. An authenticated remote attacker with administrator pri...
How severe is CVE-2025-6946?
CVE-2025-6946 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-6946?
Check the references section above for vendor advisories and patch information. Affected products include: Watchguard Fireware, Watchguard Firebox M270, Watchguard Firebox M290, Watchguard Firebox M370, Watchguard Firebox M390.