CVE-2025-1071

I

mproper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS allows Stored XSS via the spamBlocker module. This vulnerability requires an authenticated administrator session to a locally managed Firebox.This issue affects Fireware OS: from 12.0 through 12.5.12+701324, from 12.6 through 12.11.

References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:watchguard:fireware:*:*:*:*:*:*:*:*
OR cpe:2.3:h:watchguard:firebox_m270:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_m290:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_m370:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_m390:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_m440:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_m4600:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_m470:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_m4800:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_m5600:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_m570:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_m5800:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_m590:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_m670:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_m690:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_nv5:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_t20:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_t25:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_t40:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_t45:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_t55:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_t70:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_t80:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_t85:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:fireboxcloud:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:fireboxv:*:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:watchguard:fireware:*:*:*:*:*:*:*:*
OR cpe:2.3:h:watchguard:firebox_t15:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_t35:*:*:*:*:*:*:*:*

History

02 Mar 2026, 18:59

Type Values Removed Values Added
First Time Watchguard firebox M290
Watchguard
Watchguard firebox M390
Watchguard firebox T15
Watchguard firebox Nv5
Watchguard firebox M440
Watchguard firebox T25
Watchguard firebox M4800
Watchguard firebox T55
Watchguard fireboxv
Watchguard fireware
Watchguard firebox T45
Watchguard firebox T40
Watchguard firebox M670
Watchguard firebox M5600
Watchguard firebox M570
Watchguard firebox T85
Watchguard fireboxcloud
Watchguard firebox T80
Watchguard firebox T20
Watchguard firebox M5800
Watchguard firebox T70
Watchguard firebox M4600
Watchguard firebox T35
Watchguard firebox M690
Watchguard firebox M270
Watchguard firebox M370
Watchguard firebox M470
Watchguard firebox M590
CPE cpe:2.3:h:watchguard:firebox_t40:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_m4800:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_t85:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_m590:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_t35:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_m270:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_t45:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_m440:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_t55:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_t80:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_m670:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_t70:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_m690:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:fireboxv:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_m570:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_t20:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_nv5:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_m290:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_m370:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_m5800:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_m390:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_m4600:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_t25:*:*:*:*:*:*:*:*
cpe:2.3:o:watchguard:fireware:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:fireboxcloud:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_t15:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_m5600:*:*:*:*:*:*:*:*
cpe:2.3:h:watchguard:firebox_m470:*:*:*:*:*:*:*:*
Summary
  • (es) La vulnerabilidad de neutralización inadecuada de la entrada durante la generación de páginas web (XSS o "Cross-site Scripting") en WatchGuard Fireware OS permite XSS almacenado a través del módulo spamBlocker. Esta vulnerabilidad requiere una sesión de administrador autenticada en un Firebox administrado localmente. Este problema afecta a los sistemas operativos Fireware: desde la versión 12.0 hasta la 12.5.12+701324, desde la versión 12.6 hasta la 12.11.
References () https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2025-00001 - () https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2025-00001 - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.8

14 Feb 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-14 14:15

Updated : 2026-03-02 18:59


NVD link : CVE-2025-1071

Mitre link : CVE-2025-1071

CVE.ORG link : CVE-2025-1071


JSON object : View

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')