Impact
Improper neutralization of user-provided input in configuration fields of the Tigerpaw Technology Integration module leads to stored cross‑site scripting. When an attacker crafts malicious configuration data, it is written to the device and later rendered unescaped in the web interface, allowing arbitrary JavaScript to execute in the browsers of users who view the affected pages. This weakness can be exploited to deface the UI, steal session cookies, or conduct other client‑side attacks that could compromise credential confidentiality and session integrity.
Affected Systems
The flaw affects devices running WatchGuard Fireware OS that include the Tigerpaw module and have not applied the vendor’s patch (Fireware OS 2026.2.1, Fireware OS 12.12.1, or Fireware OS 12.5.19).
Risk and Exploitability
The CVSS base score of 4.8 indicates moderate severity, while an EPSS score of less than 1 % suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker would need administrator access to the web console to submit malicious configuration data, which would then be rendered unescaped for users, enabling the stored‑XSS attack path.
OpenCVE Enrichment