Home

Description

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Autotask Technology Integration module) allows Stored XSS.This issue affects Fireware OS 12.4 up to and including 12.11.4, 12.5 up to and including 12.5.13, and 2025.1 up to and including 2025.1.2.

PUBLISHED Reserved 2025-12-02 | Published 2025-12-04 | Updated 2025-12-05 | Assigner WatchGuard




MEDIUM: 4.8CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

Problem types

CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')

Product status

Default status
unaffected

12.4 (semver)
affected

12.5 (semver)
affected

2025.1 (semver)
affected

Credits

Simone Paganessi (https://www.linkedin.com/in/simonepaganessi) finder

References

www.watchguard.com/wgrd-psirt/advisory/wgsa-2025-00023

cve.org (CVE-2025-13938)

nvd.nist.gov (CVE-2025-13938)