Impact
The flaw is an improper neutralization of input during web‑page generation in the Autotask Technology Integration configuration of WatchGuard Fireware OS. An attacker can submit a malicious payload that is stored and later rendered on the configuration page, resulting in stored cross‑site‑scripting. When an administrator views the page, the embedded JavaScript can run, potentially stealing session cookies, revealing credentials, phishing or installing malware. The vulnerability is classified as CWE‑79.
Affected Systems
Firebox appliances running WatchGuard Fireware OS 12.4 through 12.12, 12.5 through 12.5.18, and 2025.1 through 2026.2 are affected. The vulnerability resides in the Autotask Technology Integration module accessed via the management interface.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity, while the EPSS score of <1% shows a very low probability of exploitation in the wild; it is not listed in the CISA KEV catalog. The likely attack vector is through the secured web‑based management console and requires an authenticated administrative account to inject crafted input; thereafter, arbitrary JavaScript executes in the victim’s browser. The risk is confined to legitimate administrators or compromised privileged accounts, and prompt firmware update mitigates the exposure.
OpenCVE Enrichment