Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (ConnectWise Technology Integration module) allows Stored XSS. This vulnerability is an additional unmitigated attack path for CVE-2025-13937.
Published: 2026-07-02
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper neutralization of input during web page generation in the ConnectWise Technology Integration module of WatchGuard Fireware OS, allowing stored cross‑site scripting. In stored XSS an attacker can embed malicious script payloads into data that is subsequently displayed to users of the web interface. If an attacker can insert such data into the integration configuration, the script will be automatically executed whenever a privileged user views that configuration in the web interface. This can lead to theft of session cookies, execution of unauthorized commands, or compromise of privileged accounts. The weakness corresponds to CWE‑79. Based on the description, it is inferred that exploitation requires the ability to modify the ConnectWise integration configuration.

Affected Systems

The flaw resides in the ConnectWise Technology Integration module of WatchGuard Fireware OS. Firmware releases prior to Fireware OS 2026.2.1, 12.12.1, and 12.5.19 are affected because the patch is included in those versions.

Risk and Exploitability

The base CVSS score of 4.8 denotes moderate severity. The EPSS score of less than 1 % indicates that exploitation is considered unlikely but still possible. The vulnerability is not listed in the CISA KEV catalog. Exploitation would involve inserting malicious script into the integration configuration, which is then rendered in the administrative interface. The likely attack vector is stored injection through the ConnectWise module, as inferred from the description.

Generated by OpenCVE AI on August 10, 2026 at 23:11 UTC.

Remediation

Vendor Solution

Fireware OS 2026.2.1, Fireware OS 12.12.1, Fireware OS 12.5.19


OpenCVE Recommended Actions

  • Update WatchGuard Fireware OS to a version that includes the CVE‑2026‑13374 fix (Fireware OS 2026.2.1, 12.12.1, or 12.5.19).
  • Remove any existing malicious or suspicious scripts from the ConnectWise integration configuration and reset to a known safe state.
  • Restrict administrative or privileged access to the ConnectWise integration module or disable the component if it is not required.

Generated by OpenCVE AI on August 10, 2026 at 23:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 10 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (ConnectWise Technology Integration module) allows Stored XSS. This vulnerability is an additional unmitigated attack path for CVE-2025-13937. This issue affects Fireware OS 12.4 up to and including 12.12, 12.5 up to and including 12.5.18, and 2025.1 up to and including 2026.2. Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (ConnectWise Technology Integration module) allows Stored XSS. This vulnerability is an additional unmitigated attack path for CVE-2025-13937.
CPEs cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.4
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.5
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:2025.1
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:*
References

Tue, 07 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 03 Jul 2026 14:45:00 +0000


Thu, 02 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (ConnectWise Technology Integration module) allows Stored XSS. This vulnerability is an additional unmitigated attack path for CVE-2025-13937. This issue affects Fireware OS 12.4 up to and including 12.12, 12.5 up to and including 12.5.18, and 2025.1 up to and including 2026.2.
Title WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in ConnectWise Technology Integration Configuration
First Time appeared Watchguard
Watchguard fireware Os
Weaknesses CWE-79
CPEs cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.4
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.5
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:2025.1
Vendors & Products Watchguard
Watchguard fireware Os
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Watchguard Firebox M270 Firebox M290 Firebox M295 Firebox M370 Firebox M390 Firebox M395 Firebox M440 Firebox M4600 Firebox M470 Firebox M4800 Firebox M495 Firebox M5600 Firebox M570 Firebox M5800 Firebox M590 Firebox M595 Firebox M670 Firebox M690 Firebox M695 Firebox Nv5 Firebox T115-w Firebox T125 Firebox T125-w Firebox T145 Firebox T145-w Firebox T15 Firebox T185 Firebox T20 Firebox T25 Firebox T35 Firebox T40 Firebox T45 Firebox T55 Firebox T70 Firebox T80 Firebox T85 Fireboxcloud Fireboxv Fireware Fireware Os
cve-icon MITRE

Status: PUBLISHED

Assigner: WatchGuard

Published:

Updated: 2026-08-10T17:16:25.059Z

Reserved: 2026-06-25T20:31:06.991Z

Link: CVE-2026-13374

cve-icon Vulnrichment

Updated: 2026-07-06T18:04:58.260Z

cve-icon NVD

Status : Modified

Published: 2026-07-03T00:16:51.257

Modified: 2026-08-10T18:17:40.010

Link: CVE-2026-13374

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-10T23:15:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')