Impact
The vulnerability is an improper neutralization of input during web‑page generation in the Autotask Technology Integration configuration of WatchGuard Fireware OS. An authenticated administrator can submit malicious input that is stored and subsequently rendered on the configuration page, resulting in stored cross‑site‑scripting. When an administrator later views this page, the embedded JavaScript can execute in their browser, potentially stealing session cookies, exposing credentials, enabling phishing attacks or installing malware. The flaw is classified as CWE‑79.
Affected Systems
Firebox appliances running WatchGuard Fireware OS versions 12.4 through 12.12, 12.5 through 12.5.18, and 2025.1 through 2026.2 are affected. The vulnerability resides in the Autotask Technology Integration module accessed via the management interface.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity, while the EPSS score of <1% shows a very low probability of exploitation in the wild; it is not listed in the CISA KEV catalog. The likely attack vector is through the secured web‑based management console and requires an authenticated administrative account to inject crafted input; thereafter, arbitrary JavaScript executes in the victim’s browser. The risk is confined to legitimate administrators or compromised privileged accounts, and a firmware update mitigates the exposure.
OpenCVE Enrichment