Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Tigerpaw Technology Integration module) allows Stored XSS. This vulnerability is an additional unmitigated attack path for CVE-2025-13936.


This issue affects Fireware OS 12.4 up to and including 12.12, 12.5 up to and including 12.5.18, and 2025.1 up to and including 2026.2.
Published: 2026-07-02
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a stored cross‑site scripting flaw (CWE‑79) located in the Tigerpaw Technology Integration module of WatchGuard Fireware OS. Improper neutralization of user input allows a malicious attacker to embed script code into configuration fields that is then rendered unescaped when the web interface is visited, creating a stored‑XSS attack path that can affect any user who accesses the affected pages. This vulnerability is an additional unmitigated attack path for CVE‑2025‑13936.

Affected Systems

WatchGuard Fireware OS versions 12.4 through 12.12, 12.5 through 12.5.18, and 2025.1 through 2026.2 are affected.

Risk and Exploitability

The CVSS score of 4.8 indicates moderate severity, while an EPSS score of less than 1% indicates a very low probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, and it is an additional unmitigated attack path for CVE‑2025‑13936. Based on the description, it is inferred that attackers could potentially gain access to the Fireware web console and supply malicious input through configuration interfaces that are later rendered unescaped; a successful injection would allow execution of arbitrary script in the context of any user viewing the affected pages.

Generated by OpenCVE AI on July 21, 2026 at 10:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest vendor patch that addresses the stored‑XSS weakness in the Tigerpaw module.
  • Remove or disable the Tigerpaw Technology Integration module to eliminate the stored‑XSS surface.
  • Limit access to the Fireware web interface to authorized administrators and restrict network exposure of the console.
  • Check the vendor’s website or security portal regularly for patches or advisories and apply updates promptly.

Generated by OpenCVE AI on July 21, 2026 at 10:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Tigerpaw Technology Integration module) allows Stored XSS. This vulnerability is an additional unmitigated attack path for CVE-2025-13936. This issue affects Fireware OS 12.4 up to and including 12.12, 12.5 up to and including 12.5.18, and 2025.1 up to and including 2026.2.
Title WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Tigerpaw Technology Integration Configuration
First Time appeared Watchguard
Watchguard fireware Os
Weaknesses CWE-79
CPEs cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.4
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.5
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:2025.1
Vendors & Products Watchguard
Watchguard fireware Os
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Watchguard Fireware Os
cve-icon MITRE

Status: PUBLISHED

Assigner: WatchGuard

Published:

Updated: 2026-07-06T15:47:29.819Z

Reserved: 2026-06-25T20:30:45.709Z

Link: CVE-2026-13373

cve-icon Vulnrichment

Updated: 2026-07-06T15:47:26.732Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T10:45:02Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')