CVE-2025-6999

Summary

An HTTP Request Smuggling [CWE-444] vulnerability in the Authentication portal of WatchGuard Fireware OS allows a remote attacker to evade request parameter sanitation and perform a reflected self-Cross-Site Scripting (XSS) attack.

WatchGuard does not believe there is a practical exploit chain with a meaningful security impact for this vulnerability.

Affected Software

VendorProductVersion RangeStatus
WatchGuardFireware OS12.0 < 12.11.3affected

Weaknesses

  • CWE-444: CWE-444

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References