Impact
Based on the description, the vulnerability is a CWE-79 stored cross‑site scripting flaw within the spamBlocker module of WatchGuard Fireware OS. An attacker who can write arbitrary content to the module’s configuration can inject malicious JavaScript that is permanently stored and later rendered within the web interface of any user who views that configuration. When the script executes, it runs with the privileges of the victim’s browser and can harvest session cookies, perform credential theft, or deliver additional payloads in the victim’s context.
Affected Systems
WatchGuard Fireware OS releases 12.0 through 12.12, 12.5 through 12.5.18, and 2025.1 through 2026.2 contain the vulnerable spamBlocker module. All listed versions are affected until a patch is applied.
Risk and Exploitability
Based on the CVSS score of 4.8 provided in the advisory, the vulnerability has moderate severity. The EPSS score of < 1% indicates a low likelihood of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an authenticated administrator who submits a crafted configuration via the web‑based interface of the spamBlocker module; once the payload is stored, it remains until the configuration is removed or the system is patched. Based on the described stored nature of the flaw, it is inferred that any user who later accesses the affected settings could be exposed, potentially leading to data theft or session hijacking.
OpenCVE Enrichment