CVE-2025-1071

CVSS 4.8 - MEDIUM
Description

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS allows Stored XSS via the spamBlocker module. This vulnerability requires an authenticated administrator session to a locally managed Firebox.This issue affects Fireware OS: from 12.0 through 12.5.12+701324, from 12.6 through 12.11.

Affected Products
29
Vendor Product Version
watchguard fireware All versions
watchguard firebox_m270 All versions
watchguard firebox_m290 All versions
watchguard firebox_m370 All versions
watchguard firebox_m390 All versions
watchguard firebox_m440 All versions
watchguard firebox_m4600 All versions
watchguard firebox_m470 All versions
watchguard firebox_m4800 All versions
watchguard firebox_m5600 All versions
watchguard firebox_m570 All versions
watchguard firebox_m5800 All versions
watchguard firebox_m590 All versions
watchguard firebox_m670 All versions
watchguard firebox_m690 All versions
watchguard firebox_nv5 All versions
watchguard firebox_t20 All versions
watchguard firebox_t25 All versions
watchguard firebox_t40 All versions
watchguard firebox_t45 All versions
watchguard firebox_t55 All versions
watchguard firebox_t70 All versions
watchguard firebox_t80 All versions
watchguard firebox_t85 All versions
watchguard fireboxcloud All versions
watchguard fireboxv All versions
watchguard fireware All versions
watchguard firebox_t15 All versions
watchguard firebox_t35 All versions
Weakness Types
CWE-79
CVE Information
CVE ID:
CVE-2025-1071
Published:
2025-02-14
Modified:
2026-03-02
CVSS Score:
4.8
Severity:
MEDIUM
Vector:
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Affected Vendors
watchguard
Quick Actions
CVSS Severity Scale
0.0 - 3.9 LOW
4.0 - 6.9 MEDIUM
7.0 - 8.9 HIGH
9.0 - 10.0 CRITICAL