Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS spamBlocker module allows Stored XSS. This vulnerability is an additional unmitigated attack path for CVE-2025-1071.

This issue affects Fireware OS 12.0 up to and including 12.12, 12.5 up to and including 12.5.18, and 2025.1 up to and including 2026.2.
Published: 2026-07-02
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is a CWE‑79 stored cross‑site scripting vulnerability in the spamBlocker module of WatchGuard Fireware OS. An attacker that can write arbitrary content to the module’s configuration can inject malicious JavaScript that is permanently stored and later rendered within the web interface of any user who views that configuration. When executed, the script runs with the privileges of the victim’s browser and can harvest session cookies, perform credential theft, or execute further payloads within the user’s context.

Affected Systems

WatchGuard Fireware OS releases 12.0 through 12.12, 12.5 through 12.5.18, and 2025.1 through 2026.2 contain the vulnerable spamBlocker module. All versions listed are affected until a patch is applied.

Risk and Exploitability

The CVSS score of 4.8 denotes moderate severity, while the EPSS score of < 1% indicates a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The attack vector is likely an authenticated administrator who submits a crafted configuration via the web‑based interface of the spamBlocker module; once the payload is stored, it remains until the configuration is removed or the system is patched. The stored nature of the flaw means that any user who later accesses the affected settings could be exposed, potentially leading to data theft or session hijacking.

Generated by OpenCVE AI on July 22, 2026 at 13:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update all vulnerable Fireware OS installations to the latest release that patches the stored XSS flaw in the spamBlocker module.
  • If no patch is immediately available, disable the spamBlocker module or restrict its configuration interface so that only trusted administrators can access it.
  • Identify and remove any malicious script payloads that have already been stored in the spamBlocker settings, and ensure input validation and output encoding are properly applied before re‑enabling the module.

Generated by OpenCVE AI on July 22, 2026 at 13:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS spamBlocker module allows Stored XSS. This vulnerability is an additional unmitigated attack path for CVE-2025-1071. This issue affects Fireware OS 12.0 up to and including 12.12, 12.5 up to and including 12.5.18, and 2025.1 up to and including 2026.2.
Title WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in spamBlocker Module
First Time appeared Watchguard
Watchguard fireware Os
Weaknesses CWE-79
CPEs cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.0
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.5
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:2025.1
Vendors & Products Watchguard
Watchguard fireware Os
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Watchguard Fireware Os
cve-icon MITRE

Status: PUBLISHED

Assigner: WatchGuard

Published:

Updated: 2026-07-06T15:03:24.964Z

Reserved: 2026-06-25T20:34:53.978Z

Link: CVE-2026-13376

cve-icon Vulnrichment

Updated: 2026-07-06T15:03:20.410Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-22T13:30:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')