Executive brief
WatchGuard Fireware OS is a firewall appliance used to protect corporate networks. A stored cross-site scripting (XSS) vulnerability in the Autotask Technology Integration configuration module allows an authenticated attacker to inject malicious scripts that are permanently stored and executed in the context of other administrators' browsers. This could lead to unauthorized configuration changes, credential theft, or complete compromise of firewall management.
Technical details
The vulnerability is a CWE-79 improper neutralization of input during web page generation, classified as stored XSS (CAPEC-592). The flaw exists in the Autotask Technology Integration module of WatchGuard Fireware OS, where user-supplied input is not properly sanitized before being stored and rendered in the web-based administrative interface. An authenticated attacker can inject malicious JavaScript code through configuration fields, which is then executed whenever other administrators access the affected configuration page. Patches are available: Fireware OS 2025.1.3, 12.11.5, and 12.5.14 address this issue. No active exploitation in the wild has been reported.
Affected products
- WatchGuard Fireware OS 12.0 to 12.11.4, 12.5.0 to 12.5.13, 2025.1.0 to 2025.1.2
Timeline
- 2025-12-04: disclosed
- 2025-12-04: patched: Fireware OS 2025.1.3, 12.11.5, 12.5.14 released