CVE Feed

    Dashboard / CVE / CVE-2025-0178

    CVE-2025-0178

    An Improper Input Validation vulnerability in WatchGuard Fireware OS allows an attacker with network access to manipulate the value of the HTTP Host header in requests sent to the Web UI. An attacker could exploit this vulnerability to redirect users to malicious websites, poison the web cache, or inject malicious JavaScript into responses sent by the Web UI.

    Published:Feb 14, 2025
    Last Modified:Aug 8, 2026
    EPS:Feb 14, 2025
    EPSS Score:0.00224
    CVSS Score:6.1

    Affected Products

    Vendor
    Watchguard
    Product
    Firebox M270
    Vendor
    Watchguard
    Product
    Firebox M290
    Vendor
    Watchguard
    Product
    Firebox M370
    Vendor
    Watchguard
    Product
    Firebox M390
    Vendor
    Watchguard
    Product
    Firebox M440
    Vendor
    Watchguard
    Product
    Firebox M4600
    Vendor
    Watchguard
    Product
    Firebox M470
    Vendor
    Watchguard
    Product
    Firebox M4800
    Vendor
    Watchguard
    Product
    Firebox M5600
    Vendor
    Watchguard
    Product
    Firebox M570
    Vendor
    Watchguard
    Product
    Firebox M5800
    Vendor
    Watchguard
    Product
    Firebox M590
    Vendor
    Watchguard
    Product
    Firebox M670
    Vendor
    Watchguard
    Product
    Firebox M690
    Vendor
    Watchguard
    Product
    Firebox Nv5
    Vendor
    Watchguard
    Product
    Firebox T15
    Vendor
    Watchguard
    Product
    Firebox T20
    Vendor
    Watchguard
    Product
    Firebox T25
    Vendor
    Watchguard
    Product
    Firebox T35
    Vendor
    Watchguard
    Product
    Firebox T40
    Vendor
    Watchguard
    Product
    Firebox T45
    Vendor
    Watchguard
    Product
    Firebox T55
    Vendor
    Watchguard
    Product
    Firebox T70
    Vendor
    Watchguard
    Product
    Firebox T80
    Vendor
    Watchguard
    Product
    Firebox T85
    Vendor
    Watchguard
    Product
    Fireboxcloud
    Vendor
    Watchguard
    Product
    Fireboxv
    Vendor
    Watchguard
    Product
    Fireware
    Vendor
    Watchguard
    Product
    Fireware Os

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High