Executive brief
WatchGuard Fireware OS is the operating system running WatchGuard Firebox firewalls, which protect corporate networks from threats. A stored cross-site scripting (XSS) vulnerability in the ConnectWise Technology Integration configuration module allows attackers who can access the web interface to inject malicious scripts that execute when administrators view the affected configuration pages, potentially enabling session hijacking, credential theft, or further network compromise.
Technical details
The vulnerability is a stored XSS (CWE-79) in the ConnectWise Technology Integration configuration module of WatchGuard Fireware OS. The root cause is improper neutralization of user input during web page generation, allowing an attacker to inject malicious JavaScript that persists in the application's database. An authenticated attacker with access to the web management interface can inject a payload into ConnectWise integration settings; when an administrator subsequently views this configuration, the stored script executes in their browser context. This requires authentication to the Fireware OS web UI. Patches are available: Fireware OS 2025.1.3, 12.11.5, and 12.5.14 address the vulnerability. No public exploitation has been reported.
Affected products
- WatchGuard Fireware OS Default and T15/T35: versions before 2025.1.3 (2025.1.x series), before 12.11.5 (12.x series), before 12.5.14 (12.5.x series)
Timeline
- 2025-12-04: disclosed
- 2025-12-04: patched: Fixes available in Fireware OS 2025.1.3, 12.11.5, and 12.5.14