Stored Cross-Site Scripting in WatchGuard Fireware OS
CVE-2025-1239
What is CVE-2025-1239?
An improperly handled input during web page generation in WatchGuard Fireware OS leads to a Stored Cross-Site Scripting (XSS) vulnerability. This security flaw allows attackers to inject malicious scripts into the Blocked Sites list. Exploitation of this vulnerability necessitates an authenticated administrator session on a locally managed Firebox, posing significant risks to the integrity and confidentiality of the system. Affected versions range from 12.0 through 12.5.12+701324 and 12.6 through 12.11, emphasizing the critical need for vigilant security measures and prompt updates.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Fireware OS 12.0 <= 12.5.12+701324
Fireware OS 12.6 <= 12.11
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
