CVE-2025-6999: WatchGuard Fireware OS

Medium severity, CVSS 6.9. EPSS: 0.4% chance of exploitation in the next 30 days.

An HTTP Request Smuggling [CWE-444] vulnerability in the Authentication portal of WatchGuard Fireware OS allows a remote attacker to evade request parameter sanitation and perform a reflected self-Cross-Site Scripting (XSS) attack. WatchGuard does not believe there is a practical exploit chain with a meaningful security impact for this vulnerability.

Affected products

  • WatchGuard Fireware OS: from 12.0, before 12.11.3 (fixed in 12.11.3)

Published 2025-09-15. Last modified 2026-08-10.