Executive brief
WatchGuard Firebox is a network security appliance used to protect corporate networks. The management interface contains a stored cross-site scripting vulnerability in the IPS configuration section that allows authenticated administrators to inject malicious code, which then executes when other administrators access the interface, potentially leading to credential theft or further system compromise.
Technical details
A stored XSS vulnerability (CWE-79) exists in the IPS configuration component of the WatchGuard Firebox management interface due to improper input sanitization. An authenticated remote attacker with administrator privileges can inject arbitrary JavaScript code via IPS configuration fields; this payload is stored and executed in the browsers of other management users when they view the configuration. The vulnerability requires valid administrator credentials and authenticated access to the management interface. An attacker can execute arbitrary JavaScript in the context of the management interface, potentially capturing session tokens or performing unauthorized administrative actions. Patches are available: Fireware OS 12.11.3 for Default appliances and 12.5.13 for T15/T35 models.
Affected products
- WatchGuard Firebox Fireware OS Default >= 12.0, < 12.11.3; Fireware OS T15/T35 >= 12.0, < 12.5.13
Timeline
- 2025-12-04: disclosed
- 2025-12-04: patched: Fireware OS 12.11.3 (Default) and 12.5.13 (T15/T35) released