THREAT OPS › Threat News › [NVD] CVE-2025-0178 (MEDIUM 6.1) — An Improper Input Validation vulnerability in WatchGuard Fireware OS allows an attacker with network access to manipulate the value of the HTTP Host header in requests sent to the Web UI. An attacker could exploit this vulnerability to redirect users to malicious websites, poison
[NVD] CVE-2025-0178 (MEDIUM 6.1) — An Improper Input Validation vulnerability in WatchGuard Fireware OS allows an attacker with network access to manipulate the value of the HTTP Host header in requests sent to the Web UI. An attacker could exploit this vulnerability to redirect users to malicious websites, poison
CVE-2025-0178 CVSS: 6.1 MEDIUM Published: 2025-02-14T14:15:32.403
An Improper Input Validation vulnerability in WatchGuard Fireware OS allows an attacker with network access to manipulate the value of the HTTP Host header in requests sent to the Web UI. An attacker could exploit this vulnerability to redirect users to malicious websites, poison the web cache, or inject malicious JavaScript into r
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- CVE-2025-0178cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-0178