WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in SIP Proxy Configuration
Summary
| CVE | CVE-2025-6947 |
|---|---|
| State | PUBLISHED |
| Assigner | WatchGuard |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2025-09-15 22:15:34 UTC |
| Updated | 2026-08-08 00:16:34 UTC |
| Description | A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the SIP Proxy configuration. An authenticated remote attacker with administrator privileges could exploit this vulnerability to execute arbitrary JavaScript code in the Firebox management interface of another management user. |
Risk And Classification
Primary CVSS: v4.0 4.8 MEDIUM from 5d1c2695-1a31-4499-88ae-e847036fd7e3
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Problem Types: CWE-79 | CWE-79 CWE-79
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | 5d1c2695-1a31-4499-88ae-e847036fd7e3 | Secondary | 4.8 | MEDIUM | CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/C... |
| 4.0 | CNA | DECLARED | 4.8 | MEDIUM | CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N |
CVSS v4.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowAttack Requirements
NonePrivileges Required
HighUser Interaction
PassiveConfidentiality
NoneIntegrity
NoneAvailability
NoneSub Conf.
LowSub Integrity
LowSub Availability
NoneCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | WatchGuard | Fireware OS | affected 12.0 12.11.3 custom | Default |
| CNA | WatchGuard | Fireware OS | affected 12.0 12.5.13 custom | T15/T35 |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.watchguard.com/wgrd-psirt/advisory/wgsa-2025-00012 | 5d1c2695-1a31-4499-88ae-e847036fd7e3 | www.watchguard.com | |
| psirt.watchguard.com/CVE-2025-6947 | 5d1c2695-1a31-4499-88ae-e847036fd7e3 | psirt.watchguard.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
Solutions
CNA: Fireware OS 12.11.3, Fireware OS 12.5.13
Exploits
CNA: WatchGuard is not aware of any exploitation of this vulnerability in the wild.
There are currently no legacy QID mappings associated with this CVE.