CVE-2025-6999EPSS p36.5%
CVE-2025-6999CVE-2025-6999
Description
An HTTP Request Smuggling [CWE-444] vulnerability in the Authentication portal of WatchGuard Fireware OS allows a remote attacker to evade request parameter sanitation and perform a reflected self-Cross-Site Scripting (XSS) attack.
WatchGuard does not believe there is a practical exploit chain with a meaningful security impact for this vulnerability.
Scoring
| EPSS | 0.45% probability of exploitation · percentile 36.5% · 2026-10-05T12:00:23Z |
| Last modified | 2026-08-10 |