Executive brief
A security vulnerability exists in the Autotask integration module of WatchGuard Firebox firewalls, which are used to secure corporate networks and manage IT services. An attacker with high-level administrative access could inject malicious scripts into the management interface. If another administrator views the affected configuration page, the script could execute, potentially leading to unauthorized actions within the management console or session hijacking.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in the Autotask Technology Integration module of WatchGuard Fireware OS due to improper neutralization of user-supplied input during web page generation. An attacker with high privileges (PR:H) can inject malicious scripts into the configuration settings. When a victim administrator interacts with the affected module via the web management interface, the script executes in their browser session. This vulnerability represents an additional attack path for issues previously identified in CVE-2025-13938. Patches are available in versions 12.12.1 and 2026.2.1, though some legacy models (T15/T35) remain unresolved.
Affected products
- WatchGuard Fireware OS 12.4 through 12.12, 12.5 through 12.5.18, 2025.1 through 2026.2
Timeline
- 2026-07-02: disclosed
- 2026-07-02: advisory
- 2026-07-02: patched