Impact
The flaw is a CWE‑79 stored cross‑site scripting vulnerability in the spamBlocker module of WatchGuard Fireware OS. An attacker that can write arbitrary content to the module’s configuration can inject malicious JavaScript that is permanently stored and later rendered within the web interface of any user who views that configuration. When executed, the script runs with the privileges of the victim’s browser and can harvest session cookies, perform credential theft, or execute further payloads within the user’s context.
Affected Systems
WatchGuard Fireware OS releases 12.0 through 12.12, 12.5 through 12.5.18, and 2025.1 through 2026.2 contain the vulnerable spamBlocker module. All versions listed are affected until a patch is applied.
Risk and Exploitability
The CVSS score of 4.8 denotes moderate severity, while the EPSS score of < 1% indicates a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The attack vector is likely an authenticated administrator who submits a crafted configuration via the web‑based interface of the spamBlocker module; once the payload is stored, it remains until the configuration is removed or the system is patched. The stored nature of the flaw means that any user who later accesses the affected settings could be exposed, potentially leading to data theft or session hijacking.
OpenCVE Enrichment