Medium severityNVD Advisory· Published Sep 15, 2025· Updated Aug 10, 2026
CVE-2025-6999
CVE-2025-6999
Description
An HTTP Request Smuggling [CWE-444] vulnerability in the Authentication portal of WatchGuard Fireware OS allows a remote attacker to evade request parameter sanitation and perform a reflected self-Cross-Site Scripting (XSS) attack.
WatchGuard does not believe there is a practical exploit chain with a meaningful security impact for this vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: 12.0 - 12.11.2
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.