Impact
Improper neutralization of input during web page generation (CWE‑79) in WatchGuard Fireware OS SIP Proxy module creates a stored Cross‑Site Scripting flaw. A malicious actor can inject scripts into SIP Proxy configuration entries, which are then persisted and executed whenever any user views the configuration page in the web interface. This provides an additional unmitigated attack path for CVE‑2025‑6947.
Affected Systems
WatchGuard Fireware OS versions 12.0 through 12.12, 12.5 through 12.5.18, and 2025.1 through 2026.2 are affected.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity, while the EPSS score of <1% suggests a very low probability of exploitation. The flaw allows injection of persistent scripts into the SIP Proxy configuration; the likely attack vector is the web‑based configuration interface, though the required privileges are not explicitly stated. The vulnerability is not listed in the CISA KEV catalog, reducing the likelihood of widespread exploitation.
OpenCVE Enrichment