Junglewise Threat Intelligence

CVE-2025-13938: WatchGuard Fireware OS stored XSS in Autotask Technology Integration

CVE-2025-13938 · Severity: medium · CVSS 6.1 · Published 2025-12-04

Technologies: Watchguard Fireware OS. Vendors: Watchguard.

Executive brief

WatchGuard Fireware OS is a firewall appliance used to protect corporate networks. A stored cross-site scripting (XSS) vulnerability in the Autotask Technology Integration configuration module allows an authenticated attacker to inject malicious scripts that are permanently stored and executed in the context of other administrators' browsers. This could lead to unauthorized configuration changes, credential theft, or complete compromise of firewall management.

Technical details

The vulnerability is a CWE-79 improper neutralization of input during web page generation, classified as stored XSS (CAPEC-592). The flaw exists in the Autotask Technology Integration module of WatchGuard Fireware OS, where user-supplied input is not properly sanitized before being stored and rendered in the web-based administrative interface. An authenticated attacker can inject malicious JavaScript code through configuration fields, which is then executed whenever other administrators access the affected configuration page. Patches are available: Fireware OS 2025.1.3, 12.11.5, and 12.5.14 address this issue. No active exploitation in the wild has been reported.

Affected products

  • WatchGuard Fireware OS 12.0 to 12.11.4, 12.5.0 to 12.5.13, 2025.1.0 to 2025.1.2

Timeline

  • 2025-12-04: disclosed
  • 2025-12-04: patched: Fireware OS 2025.1.3, 12.11.5, 12.5.14 released

References

Related threats