Junglewise Threat Intelligence

CVE-2025-13936: WatchGuard Fireware OS stored XSS in Tigerpaw integration

CVE-2025-13936 · Severity: medium · CVSS 6.1 · Published 2025-12-04

Technologies: Watchguard Fireware OS. Vendors: Watchguard.

Executive brief

WatchGuard Firebox firewalls include a Tigerpaw Technology integration module for managing business operations and customer data. A stored cross-site scripting (XSS) vulnerability in this module allows an authenticated attacker to inject malicious code that persists in the system and executes when administrators view affected configuration pages, potentially compromising administrative sessions or enabling further attacks.

Technical details

This is a stored XSS vulnerability (CWE-79) in the Tigerpaw Technology Integration configuration component of WatchGuard Fireware OS. The vulnerability arises from improper neutralization of user input during web page generation, allowing an attacker to inject persistent malicious scripts. An authenticated user can craft specially-crafted input that gets stored in the system and subsequently executed in the browser context of other administrators who access the affected configuration pages. This could lead to session hijacking, credential theft, or privilege escalation. Patches are available: Fireware OS 2025.1.3, 12.11.5, and 12.5.14.

Affected products

  • WatchGuard Fireware OS Default: >= 12.0, < 12.11.5; T15/T35: >= 12.0, < 12.5.14; 2025.1: >= 2025.1, < 2025.1.3

Timeline

  • 2025-12-04: disclosed
  • 2025-12-04: patched: Fireware OS 2025.1.3, 12.11.5, and 12.5.14

References

Related threats