Improper Input Validation in WatchGuard Fireware OS Exposure
CVE-2025-0178
5.1MEDIUM
Summary
A vulnerability in WatchGuard Fireware OS relates to improper input validation that can potentially be exploited by attackers. By manipulating the value of the HTTP Host header in requests sent to the Web UI, adversaries could redirect users to malicious sites, poison the web cache, or inject harmful JavaScript into the responses. This compromise impacts all versions of Fireware OS from 12.0 to 12.11, highlighting the need for immediate attention to ensure user security and system integrity.
Affected Version(s)
Fireware OS 12.0 <= 12.5.12+701324
Fireware OS 12.6.0 <= 12.11
References
CVSS V4
Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved