Junglewise Threat Intelligence

CVE-2025-13939: WatchGuard Fireware OS stored XSS in Gateway Wireless Controller

CVE-2025-13939 · Severity: medium · CVSS 6.1 · Published 2025-12-04

Technologies: Watchguard Fireware OS. Vendors: Watchguard.

Executive brief

WatchGuard Fireware OS is the core operating system for WatchGuard Firebox network security appliances. A stored cross-site scripting (XSS) vulnerability in the Gateway Wireless Controller module allows an attacker to inject malicious scripts that persist in the system and execute in the browsers of administrators accessing the web interface, potentially enabling account hijacking or unauthorized configuration changes.

Technical details

This is a CWE-79 improper neutralization of input during web page generation vulnerability affecting the Gateway Wireless Controller module in WatchGuard Fireware OS. The vulnerability allows stored XSS, meaning malicious input is permanently saved and executed whenever an authenticated user views the affected page. The attack requires network access to the Fireware OS web management interface and does not require prior authentication to inject the payload, though execution occurs when administrators access the interface. An attacker can inject arbitrary JavaScript code that runs in the context of the admin's session, potentially leading to session hijacking or unauthorized changes to firewall configuration. Patches are available: Fireware OS 2025.1.3, 12.11.5, and 12.5.14 for T15/T35 models address the vulnerability.

Affected products

  • WatchGuard Fireware OS 2025.1 < 2025.1.3, 12.0 < 12.11.5, 11.7.2 <= 11.12.4

Timeline

  • 2025-12-04: disclosed

References

Related threats