Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS spamBlocker module allows Stored XSS. This vulnerability is an additional unmitigated attack path for CVE-2025-1071.

This issue affects Fireware OS 12.0 up to and including 12.12, 12.5 up to and including 12.5.18, and 2025.1 up to and including 2026.2.
Published: 2026-07-02
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Based on the description, the vulnerability is a CWE-79 stored cross‑site scripting flaw within the spamBlocker module of WatchGuard Fireware OS. An attacker who can write arbitrary content to the module’s configuration can inject malicious JavaScript that is permanently stored and later rendered within the web interface of any user who views that configuration. When the script executes, it runs with the privileges of the victim’s browser and can harvest session cookies, perform credential theft, or deliver additional payloads in the victim’s context.

Affected Systems

WatchGuard Fireware OS releases 12.0 through 12.12, 12.5 through 12.5.18, and 2025.1 through 2026.2 contain the vulnerable spamBlocker module. All listed versions are affected until a patch is applied.

Risk and Exploitability

Based on the CVSS score of 4.8 provided in the advisory, the vulnerability has moderate severity. The EPSS score of < 1% indicates a low likelihood of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an authenticated administrator who submits a crafted configuration via the web‑based interface of the spamBlocker module; once the payload is stored, it remains until the configuration is removed or the system is patched. Based on the described stored nature of the flaw, it is inferred that any user who later accesses the affected settings could be exposed, potentially leading to data theft or session hijacking.

Generated by OpenCVE AI on August 1, 2026 at 21:01 UTC.

Remediation

Vendor Solution

Fireware OS 2026.2.1, Fireware OS 12.12.1, Fireware OS 12.5.19


OpenCVE Recommended Actions

  • Update all vulnerable Fireware OS installations to the latest release that patches the stored XSS flaw in the spamBlocker module.
  • If no patch is immediately available, disable the spamBlocker module or restrict its configuration interface so that only trusted administrators can access it.
  • Identify and remove any malicious script payloads that have already been stored in the spamBlocker settings, and ensure input validation and output encoding are properly applied before re‑enabling the module.

Generated by OpenCVE AI on August 1, 2026 at 21:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 10 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.0
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.5
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:2025.1
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:*
References

Mon, 06 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS spamBlocker module allows Stored XSS. This vulnerability is an additional unmitigated attack path for CVE-2025-1071. This issue affects Fireware OS 12.0 up to and including 12.12, 12.5 up to and including 12.5.18, and 2025.1 up to and including 2026.2.
Title WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in spamBlocker Module
First Time appeared Watchguard
Watchguard fireware Os
Weaknesses CWE-79
CPEs cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.0
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.5
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:2025.1
Vendors & Products Watchguard
Watchguard fireware Os
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Watchguard Firebox M270 Firebox M290 Firebox M295 Firebox M370 Firebox M390 Firebox M395 Firebox M440 Firebox M4600 Firebox M470 Firebox M4800 Firebox M495 Firebox M5600 Firebox M570 Firebox M5800 Firebox M590 Firebox M595 Firebox M670 Firebox M690 Firebox M695 Firebox Nv5 Firebox T115-w Firebox T125 Firebox T125-w Firebox T145 Firebox T145-w Firebox T15 Firebox T185 Firebox T20 Firebox T25 Firebox T35 Firebox T40 Firebox T45 Firebox T55 Firebox T70 Firebox T80 Firebox T85 Fireboxcloud Fireboxv Fireware Fireware Os
cve-icon MITRE

Status: PUBLISHED

Assigner: WatchGuard

Published:

Updated: 2026-08-10T17:18:25.413Z

Reserved: 2026-06-25T20:34:53.978Z

Link: CVE-2026-13376

cve-icon Vulnrichment

Updated: 2026-07-06T15:03:20.410Z

cve-icon NVD

Status : Modified

Published: 2026-07-03T00:16:51.497

Modified: 2026-08-10T18:17:40.303

Link: CVE-2026-13376

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T21:15:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')