Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Autotask Technology Integration module) allows Stored XSS. This vulnerability is an additional unmitigated attack path for CVE-2025-13938.


This issue affects Fireware OS 12.4 up to and including 12.12, 12.5 up to and including 12.5.18, and 2025.1 up to and including 2026.2.
Published: 2026-07-02
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is an improper neutralization of input during web‑page generation in the Autotask Technology Integration configuration of WatchGuard Fireware OS. An attacker can submit a malicious payload that is stored and later rendered on the configuration page, resulting in stored cross‑site‑scripting. When an administrator views the page, the embedded JavaScript can run, potentially stealing session cookies, revealing credentials, phishing or installing malware. The vulnerability is classified as CWE‑79.

Affected Systems

Firebox appliances running WatchGuard Fireware OS 12.4 through 12.12, 12.5 through 12.5.18, and 2025.1 through 2026.2 are affected. The vulnerability resides in the Autotask Technology Integration module accessed via the management interface.

Risk and Exploitability

The CVSS score of 4.8 indicates moderate severity, while the EPSS score of <1% shows a very low probability of exploitation in the wild; it is not listed in the CISA KEV catalog. The likely attack vector is through the secured web‑based management console and requires an authenticated administrative account to inject crafted input; thereafter, arbitrary JavaScript executes in the victim’s browser. The risk is confined to legitimate administrators or compromised privileged accounts, and prompt firmware update mitigates the exposure.

Generated by OpenCVE AI on July 24, 2026 at 11:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware release from WatchGuard that addresses this XSS flaw
  • Restrict access to the Fireware web management interface to trusted administrators only, ensuring only authenticated privileged accounts can reach the Autotask module
  • If the Autotask Technology Integration module is unnecessary, disable or uninstall it to eliminate the vulnerable code

Generated by OpenCVE AI on July 24, 2026 at 11:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 07 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Autotask Technology Integration module) allows Stored XSS. This vulnerability is an additional unmitigated attack path for CVE-2025-13938. This issue affects Fireware OS 12.4 up to and including 12.12, 12.5 up to and including 12.5.18, and 2025.1 up to and including 2026.2.
Title WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Autotask Technology Integration Configuration
First Time appeared Watchguard
Watchguard fireware Os
Weaknesses CWE-79
CPEs cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.4
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.5
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:2025.1
Vendors & Products Watchguard
Watchguard fireware Os
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Watchguard Fireware Os
cve-icon MITRE

Status: PUBLISHED

Assigner: WatchGuard

Published:

Updated: 2026-07-07T17:01:41.235Z

Reserved: 2026-06-25T20:31:08.245Z

Link: CVE-2026-13375

cve-icon Vulnrichment

Updated: 2026-07-06T18:04:55.414Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-24T11:15:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')