WatchGuard Fireware OS
cpe:2.3:o:watchguard:fireware:*:*:*:*:*:*:*
- >= 11.7.2, <= 11.12.4+541730
- >= 12.0, <= 12.11.4
- >= 12.5, <= 12.5.13
- >= 2025.1, <= 2025.1.2
A stored cross-site scripting vulnerability has been identified in WatchGuard Fireware OS within the Gateway Wireless Controller module. This issue arises from improper input neutralization during web page generation, allowing malicious scripts to be embedded and potentially executed. The vulnerability affects Fireware OS versions 11.7.2 prior to 11.12.4+541730, 12.0 prior to 12.11.4, 12.5 prior to 12.5.13, and 2025.1 prior to 2025.1.2.
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user.
Users can upgrade to Fireware OS 2025.1.3, 12.11.5, or 12.5.14 (for T15 & T35 models) to address this vulnerability. For models on Fireware OS 11.x, this version has reached end of life.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.