Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (ConnectWise Technology Integration module) allows Stored XSS. This vulnerability is an additional unmitigated attack path for CVE-2025-13937.


This issue affects Fireware OS 12.4 up to and including 12.12, 12.5 up to and including 12.5.18, and 2025.1 up to and including 2026.2.
Published: 2026-07-02
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper neutralization of input during web page generation in the ConnectWise Technology Integration module of WatchGuard Fireware OS, leading to stored cross‑site scripting. An attacker who can inject data into the integration configuration can embed a malicious script that is executed automatically whenever an administrator views the settings in the web interface. Because the script runs in the context of the admin user, it can steal session cookies, execute arbitrary commands, or otherwise compromise the confidentiality and integrity of privileged accounts.

Affected Systems

WatchGuard Fireware OS is affected. Vulnerable releases span versions 12.4 through 12.12, 12.5 through 12.5.18, and 2025.1 through 2026.2. The flaw exists in the ConnectWise Technology Integration module of these firmware versions.

Risk and Exploitability

With a CVSS base score of 4.8 the vulnerability carries a moderate severity rating, and an EPSS score of less than 1 % indicates that exploitation is unlikely but still possible. The flaw is not listed in the CISA KEV catalog. Exploitation requires an attacker to have the ability to modify the integration configuration, meaning privileged or administrative access is needed. Once injected, any user who views the configuration through the web interface may be exposed to the stored malicious script. The likely attack vector is the stored injection of script payloads into the ConnectWise integration settings, which then execute in the context of users viewing the settings in the web interface.

Generated by OpenCVE AI on July 24, 2026 at 11:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update WatchGuard Fireware OS firmware to a version that includes the fix for CVE‑2026‑13374.
  • Remove any injected scripts from the ConnectWise integration configuration or reset the integration settings to their default values.
  • Restrict administrative or privileged access to the ConnectWise Technology Integration module, and consider disabling the integration component if it is not required.

Generated by OpenCVE AI on July 24, 2026 at 11:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 07 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 03 Jul 2026 14:45:00 +0000


Thu, 02 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (ConnectWise Technology Integration module) allows Stored XSS. This vulnerability is an additional unmitigated attack path for CVE-2025-13937. This issue affects Fireware OS 12.4 up to and including 12.12, 12.5 up to and including 12.5.18, and 2025.1 up to and including 2026.2.
Title WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in ConnectWise Technology Integration Configuration
First Time appeared Watchguard
Watchguard fireware Os
Weaknesses CWE-79
CPEs cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.4
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.5
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:2025.1
Vendors & Products Watchguard
Watchguard fireware Os
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Watchguard Fireware Os
cve-icon MITRE

Status: PUBLISHED

Assigner: WatchGuard

Published:

Updated: 2026-07-07T17:01:46.872Z

Reserved: 2026-06-25T20:31:06.991Z

Link: CVE-2026-13374

cve-icon Vulnrichment

Updated: 2026-07-06T18:04:58.260Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-24T11:15:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')