Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS SIP Proxy module allows Stored XSS. This vulnerability is an additional unmitigated attack path for CVE-2025-6947.

This issue affects Fireware OS 12.0 up to and including 12.12, 12.5 up to and including 12.5.18, and 2025.1 up to and including 2026.2.
Published: 2026-07-02
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper neutralization of input during web page generation (CWE‑79) in WatchGuard Fireware OS SIP Proxy module creates a stored Cross‑Site Scripting flaw. A malicious actor can inject scripts into SIP Proxy configuration entries, which are then persisted and executed whenever any user views the configuration page in the web interface. This provides an additional unmitigated attack path for CVE‑2025‑6947.

Affected Systems

WatchGuard Fireware OS versions 12.0 through 12.12, 12.5 through 12.5.18, and 2025.1 through 2026.2 are affected.

Risk and Exploitability

The CVSS score of 4.8 indicates moderate severity, while the EPSS score of <1% suggests a very low probability of exploitation. The flaw allows injection of persistent scripts into the SIP Proxy configuration; the likely attack vector is the web‑based configuration interface, though the required privileges are not explicitly stated. The vulnerability is not listed in the CISA KEV catalog, reducing the likelihood of widespread exploitation.

Generated by OpenCVE AI on July 21, 2026 at 10:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest WatchGuard Fireware OS firmware update that contains the fix for the stored XSS flaw in the SIP Proxy module
  • Restrict access to the SIP Proxy configuration web interface to trusted privileged users and enforce strict role‑based access controls
  • If a patch cannot be applied immediately, monitor configuration changes for unexpected script content and apply input validation or sanitization to neutralize script characters in configuration pages

Generated by OpenCVE AI on July 21, 2026 at 10:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS SIP Proxy module allows Stored XSS. This vulnerability is an additional unmitigated attack path for CVE-2025-6947. This issue affects Fireware OS 12.0 up to and including 12.12, 12.5 up to and including 12.5.18, and 2025.1 up to and including 2026.2.
Title WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in SIP Proxy Configuration
First Time appeared Watchguard
Watchguard fireware Os
Weaknesses CWE-79
CPEs cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.0
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:12.5
cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:2025.1
Vendors & Products Watchguard
Watchguard fireware Os
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Watchguard Fireware Os
cve-icon MITRE

Status: PUBLISHED

Assigner: WatchGuard

Published:

Updated: 2026-07-06T15:02:58.909Z

Reserved: 2026-06-25T20:34:54.862Z

Link: CVE-2026-13377

cve-icon Vulnrichment

Updated: 2026-07-06T15:02:55.650Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T10:45:02Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')