CVE-2025-0178
Severity CVSS v4.0:
MEDIUM
Type:
CWE-20
Input Validation
Publication date:
14/02/2025
Last modified:
02/03/2026
Description
Improper Input Validation vulnerability in WatchGuard Fireware OS allows an attacker to manipulate the value of the HTTP Host header in requests sent to the Web UI. An attacker could exploit this vulnerability to redirect users to malicious websites, poison the web cache, or inject malicious JavaScript into responses sent by the Web UI.<br />
This issue affects Fireware OS: from 12.0 up to and including 12.11.
Impact
Base Score 4.0
5.10
Severity 4.0
MEDIUM
Base Score 3.x
6.10
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:watchguard:fireware:*:*:*:*:*:*:*:* | 12.5 (including) | 12.5.13 (excluding) |
| cpe:2.3:h:watchguard:firebox_t15:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:watchguard:firebox_t35:*:*:*:*:*:*:*:* | ||
| cpe:2.3:o:watchguard:fireware:*:*:*:*:*:*:*:* | 12.0.0 (including) | 12.11.1 (excluding) |
| cpe:2.3:h:watchguard:firebox_m270:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:watchguard:firebox_m290:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:watchguard:firebox_m370:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:watchguard:firebox_m390:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:watchguard:firebox_m440:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:watchguard:firebox_m4600:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:watchguard:firebox_m470:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:watchguard:firebox_m4800:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:watchguard:firebox_m5600:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:watchguard:firebox_m570:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:watchguard:firebox_m5800:*:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



