CVE Feed

    Dashboard / CVE / CVE-2025-6946

    CVE-2025-6946

    A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the IPS configuration. An authenticated remote attacker with administrator privileges could exploit this vulnerability to execute arbitrary JavaScript code in the Firebox management ninterface of another management user.

    Published:Dec 4, 2025
    Last Modified:Aug 8, 2026
    EPS:Dec 4, 2025
    EPSS Score:0.00182
    CVSS Score:4.8

    Affected Products

    Vendor
    Watchguard
    Product
    Firebox M270
    Vendor
    Watchguard
    Product
    Firebox M290
    Vendor
    Watchguard
    Product
    Firebox M370
    Vendor
    Watchguard
    Product
    Firebox M390
    Vendor
    Watchguard
    Product
    Firebox M440
    Vendor
    Watchguard
    Product
    Firebox M4600
    Vendor
    Watchguard
    Product
    Firebox M470
    Vendor
    Watchguard
    Product
    Firebox M4800
    Vendor
    Watchguard
    Product
    Firebox M5600
    Vendor
    Watchguard
    Product
    Firebox M570
    Vendor
    Watchguard
    Product
    Firebox M5800
    Vendor
    Watchguard
    Product
    Firebox M590
    Vendor
    Watchguard
    Product
    Firebox M670
    Vendor
    Watchguard
    Product
    Firebox M690
    Vendor
    Watchguard
    Product
    Firebox Nv5
    Vendor
    Watchguard
    Product
    Firebox T15
    Vendor
    Watchguard
    Product
    Firebox T20
    Vendor
    Watchguard
    Product
    Firebox T25
    Vendor
    Watchguard
    Product
    Firebox T35
    Vendor
    Watchguard
    Product
    Firebox T40
    Vendor
    Watchguard
    Product
    Firebox T45
    Vendor
    Watchguard
    Product
    Firebox T55
    Vendor
    Watchguard
    Product
    Firebox T70
    Vendor
    Watchguard
    Product
    Firebox T80
    Vendor
    Watchguard
    Product
    Firebox T85
    Vendor
    Watchguard
    Product
    Fireboxcloud
    Vendor
    Watchguard
    Product
    Fireboxv
    Vendor
    Watchguard
    Product
    Fireware
    Vendor
    Watchguard
    Product
    Fireware Os

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High