Impact
The vulnerability is an improper neutralization of input during web page generation in the ConnectWise Technology Integration module of WatchGuard Fireware OS, leading to stored cross‑site scripting. An attacker who can inject data into the integration configuration can embed a malicious script that is executed automatically whenever an administrator views the settings in the web interface. Because the script runs in the context of the admin user, it can steal session cookies, execute arbitrary commands, or otherwise compromise the confidentiality and integrity of privileged accounts.
Affected Systems
WatchGuard Fireware OS is affected. Vulnerable releases span versions 12.4 through 12.12, 12.5 through 12.5.18, and 2025.1 through 2026.2. The flaw exists in the ConnectWise Technology Integration module of these firmware versions.
Risk and Exploitability
With a CVSS base score of 4.8 the vulnerability carries a moderate severity rating, and an EPSS score of less than 1 % indicates that exploitation is unlikely but still possible. The flaw is not listed in the CISA KEV catalog. Exploitation requires an attacker to have the ability to modify the integration configuration, meaning privileged or administrative access is needed. Once injected, any user who views the configuration through the web interface may be exposed to the stored malicious script. The likely attack vector is the stored injection of script payloads into the ConnectWise integration settings, which then execute in the context of users viewing the settings in the web interface.
OpenCVE Enrichment