cbcvebase.

Watchguard Fireware Os vulnerabilities

69 known vulnerabilities affecting watchguard/fireware_os.

Total CVEs
69
CISA KEV
2
actively exploited
Public exploits
1
Exploited in wild
2
Severity breakdown
CRITICAL7HIGH41MEDIUM21

Vulnerabilities

Page 4 of 4
CVE-2025-13938P4MEDIUMCVSS 6.1≥ 2025.1, < 2026.2.1≥ 12.4, < 12.12.1+3 more2025-12-04
CVE-2025-13938 [MEDIUM] CWE-79 CVE-2025-13938: Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerab Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Autotask Technology Integration module) allows Stored XSS.
nvd
CVE-2025-13940P4MEDIUMCVSS 5.5≥ 2025.1, < 2025.1.3≥ 12.8.1, < 12.11.52025-12-04
CVE-2025-13940 [MEDIUM] CWE-440 CVE-2025-13940: An Expected Behavior Violation [CWE-440] vulnerability in WatchGuard Fireware OS may allow an attack An Expected Behavior Violation [CWE-440] vulnerability in WatchGuard Fireware OS may allow an attacker to bypass the Fireware OS boot time system integrity check and prevent the Firebox from shutting down in the event of a system integrity check failure. The on-demand system integrity check in the Fireware Web UI will correctly show a failed system
nvd
CVE-2026-13728P4MEDIUMCVSS 4.4≥ 2025.1, < 2026.2.1≥ 12.0, < 12.12.1+1 more2026-07-03
CVE-2026-13728 [MEDIUM] CWE-798 CVE-2026-13728: In exception circumstances, WatchGuard Fireware OS on a FireCluster may use a hard-coded encryption In exception circumstances, WatchGuard Fireware OS on a FireCluster may use a hard-coded encryption key to encrypt saved credentials for Access Portal resources. This vulnerability does not affect devices that do not support the Access Portal feature or standalone Fireboxes not deployed in a FireCluster.
nvd
CVE-2025-1239P4MEDIUMCVSS 4.8≥ 12.0, < 12.11.1≥ 12.0, < 12.5.132025-02-14
CVE-2025-1239 [MEDIUM] CWE-79 CVE-2025-1239: A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard F A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the Blocked Sites list. An authenticated remote attacker with administrator privileges could exploit this vulnerability to execute arbitrary JavaScript code in the Firebox management interface of another management user.
nvd
CVE-2025-4805P4MEDIUMCVSS 4.8≥ 12.0, < 12.11.22025-05-16
CVE-2025-4805 [MEDIUM] CWE-79 CVE-2025-4805: A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard F A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the Access Portal configuration. An authenticated remote attacker with administrator privileges could exploit this vulnerability to execute arbitrary JavaScript code in the Firebox management interface of another management user.
nvd
CVE-2025-6947P4MEDIUMCVSS 4.8≥ 12.0, < 12.11.9≥ 2025.1, < 2026.2.1+2 more2025-09-15
CVE-2025-6947 [MEDIUM] CWE-79 CVE-2025-6947: A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard F A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the SIP Proxy configuration. An authenticated remote attacker with administrator privileges could exploit this vulnerability to execute arbitrary JavaScript code in the Firebox management interface of another management user.
nvd
CVE-2025-6946P4MEDIUMCVSS 4.8≥ 12.0, < 12.11.3≥ 12.0, < 12.5.132025-12-04
CVE-2025-6946 [MEDIUM] CWE-79 CVE-2025-6946: A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard F A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the IPS configuration. An authenticated remote attacker with administrator privileges could exploit this vulnerability to execute arbitrary JavaScript code in the Firebox management ninterface of another management user.
nvd
CVE-2025-4804P4MEDIUMCVSS 4.8≥ 12.0, < 12.11.2≥ 12.5, < 12.5.132025-05-16
CVE-2025-4804 [MEDIUM] CWE-79 CVE-2025-4804: Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerab Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS allows Stored XSS via the spamBlocker module. This vulnerability requires an authenticated administrator session to a locally managed Firebox.
nvd
CVE-2025-1071P4MEDIUMCVSS 4.8≥ 2025.1, < 2026.2.1≥ 12.0, < 12.12.1+2 more2025-02-14
CVE-2025-1071 [MEDIUM] CWE-79 CVE-2025-1071: A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard F A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the spamBlocker module. An authenticated remote attacker with administrator privileges could exploit this vulnerability to execute arbitrary JavaScript code in the Firebox management interface of another management user.
nvd
Watchguard Fireware Os vulnerabilities | cvebase