Impact
The vulnerability is a stored cross‑site scripting flaw (CWE‑79) located in the Tigerpaw Technology Integration module of WatchGuard Fireware OS. Improper neutralization of user input allows a malicious attacker to embed script code into configuration fields that is then rendered unescaped when the web interface is visited, creating a stored‑XSS attack path that can affect any user who accesses the affected pages. This vulnerability is an additional unmitigated attack path for CVE‑2025‑13936.
Affected Systems
WatchGuard Fireware OS versions 12.4 through 12.12, 12.5 through 12.5.18, and 2025.1 through 2026.2 are affected.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity, while an EPSS score of less than 1% indicates a very low probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, and it is an additional unmitigated attack path for CVE‑2025‑13936. Based on the description, it is inferred that attackers could potentially gain access to the Fireware web console and supply malicious input through configuration interfaces that are later rendered unescaped; a successful injection would allow execution of arbitrary script in the context of any user viewing the affected pages.
OpenCVE Enrichment