GHSA-4484-mhwr-fxpcMediumCVSS 6.1

A reflected cross-site scripting (XSS) vulnerability in the Fireware OS Web UI enabled execution...

Published
March 3, 2026
Last Modified
August 10, 2026

🔗 CVE IDs covered (1)

📋 Description

A reflected cross-site scripting (XSS) vulnerability in the Fireware OS Web UI enabled execution of malicious JavaScript in the context of an authenticated management user's browser when they click on a specially crafted link.

This vulnerability affects Fireware OS 12.7 up to and including 12.11.7 and 2025.1 up to and including 2026.1.1.

🔗 References (5)