CVE-2025-6999EPSS p42.6%
CVE-2025-6999CVE-2025-6999
Description
An HTTP Request Smuggling [CWE-444] vulnerability in the Authentication portal of WatchGuard Fireware OS allows a remote attacker to evade request parameter sanitation and perform a reflected self-Cross-Site Scripting (XSS) attack.
WatchGuard does not believe there is a practical exploit chain with a meaningful security impact for this vulnerability.
Scoring
| EPSS | 0.54% probability of exploitation · percentile 42.6% · 2026-08-11T12:00:17Z |
| Last modified | 2026-08-10 |