Impact
A reflected cross‑site scripting vulnerability in the Fireware OS Web UI allows attackers to inject and execute malicious JavaScript in the browser session of an authenticated management user when a crafted link is clicked. The flaw, classified as CWE‑79, gives an attacker the ability to run arbitrary malicious scripts while the user is logged in, potentially exposing privileged configuration data, session tokens, or enabling further lateral movement within the secured network.
Affected Systems
The flaw affects WatchGuard Fireware OS installations on a wide range of Firebox devices, including the M270, M290, M295, M370, M390, M395, M440, M4600, M470, M4800, M495, M5600, M570, M5800, M590, M595, M670, M690, M695, NV5, T115‑W, T125‑W, T125, T145‑W, T145, T185, T20, T25, T40, T45, T55, T70, T80, T85, Fireboxcloud, and Fireboxv.
Risk and Exploitability
With a CVSS score of 5.1 and an EPSS value below 1%, the vulnerability presents moderate severity but a low estimated likelihood of exploitation. The flaw requires an attacker to craft a link and persuade a legitimate management user to click it, implying a reliance on social engineering or insider assistance. Because it is not listed in CISA’s KEV catalog, there have been no confirmed large‑scale exploitations to date.
OpenCVE Enrichment