Impact
The vulnerability is an improper neutralization of input during web page generation in the ConnectWise Technology Integration module of WatchGuard Fireware OS, allowing stored cross‑site scripting. In stored XSS an attacker can embed malicious script payloads into data that is subsequently displayed to users of the web interface. If an attacker can insert such data into the integration configuration, the script will be automatically executed whenever a privileged user views that configuration in the web interface. This can lead to theft of session cookies, execution of unauthorized commands, or compromise of privileged accounts. The weakness corresponds to CWE‑79. Based on the description, it is inferred that exploitation requires the ability to modify the ConnectWise integration configuration.
Affected Systems
The flaw resides in the ConnectWise Technology Integration module of WatchGuard Fireware OS. Firmware releases prior to Fireware OS 2026.2.1, 12.12.1, and 12.5.19 are affected because the patch is included in those versions.
Risk and Exploitability
The base CVSS score of 4.8 denotes moderate severity. The EPSS score of less than 1 % indicates that exploitation is considered unlikely but still possible. The vulnerability is not listed in the CISA KEV catalog. Exploitation would involve inserting malicious script into the integration configuration, which is then rendered in the administrative interface. The likely attack vector is stored injection through the ConnectWise module, as inferred from the description.
OpenCVE Enrichment