Impact
Improper Neutralization of Input During Web Page Generation (CWE‑79) in the WatchGuard Fireware OS SIP Proxy module creates a stored Cross‑Site Scripting flaw. This flaw permits malicious actors to persist arbitrary script content in the SIP Proxy configuration, which is then executed when a user views the configuration via the web interface. Additionally, the issue constitutes an unmitigated attack path in relation to CVE‑2025‑6947.
Affected Systems
WatchGuard Fireware OS versions 12.0 through 12.12, 12.5 through 12.5.18, and 2025.1 through 2026.2 are affected.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity, while the EPSS score of <1% suggests a very low probability of exploitation. The flaw allows injection of persistent scripts into the SIP Proxy configuration; the likely attack vector is the web‑based configuration interface, though the required privileges are not explicitly stated. The vulnerability is not listed in the CISA KEV catalog, reducing the likelihood of widespread exploitation.
OpenCVE Enrichment