Vulnerability Description
An HTTP Request Smuggling [CWE-444] vulnerability in the Authentication portal of WatchGuard Fireware OS allows a remote attacker to evade request parameter sanitation and perform a reflected self-Cross-Site Scripting (XSS) attack. WatchGuard does not believe there is a practical exploit chain with a meaningful security impact for this vulnerability.
Related Weaknesses (CWE)
References
- https://psirt.watchguard.com/CVE-2025-6999
- https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2025-00014
FAQ
What is CVE-2025-6999?
CVE-2025-6999 is a documented vulnerability. An HTTP Request Smuggling [CWE-444] vulnerability in the Authentication portal of WatchGuard Fireware OS allows a remote attacker to evade request parameter sanitation and perform a reflected self-Cro...
How severe is CVE-2025-6999?
CVSS scoring is not yet available for CVE-2025-6999. Check NVD for updates.
Is there a patch for CVE-2025-6999?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.