CVE-2025-0178

EUVD-2025-1528
An Improper Input Validation vulnerability in WatchGuard Fireware OS allows an attacker with network access to manipulate the value of the HTTP Host header in requests sent to the Web UI. An attacker could exploit this vulnerability to redirect users to malicious websites, poison the web cache, or inject malicious JavaScript into responses sent by the Web UI.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 13.71%
Affected Products (NVD)
VendorProductVersion
watchguardfireware
12.0.0 ≤
𝑥
< 12.11.1
watchguardfireware
12.5 ≤
𝑥
< 12.5.13
𝑥
= Vulnerable software versions