CVE-2025-13936: WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Tigerpaw Technology Integration Configuration
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Tigerpaw Technology Integration module) allows Stored XSS.This issue affects Fireware OS 12.4 up to and including 12.11.4, 12.5 up to and including 12.5.13, and 2025.1 up to and including 2025.1.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13936?
CVE-2025-13936 is classified as a medium severity vulnerability due to its potential for stored XSS attacks.
How do I fix CVE-2025-13936?
To fix CVE-2025-13936, upgrade WatchGuard Fireware OS to version 12.12 or later where the vulnerability has been resolved.
Which versions of Fireware OS are affected by CVE-2025-13936?
CVE-2025-13936 affects Fireware OS versions from 12.4 up to and including 12.11.4 and certain versions of 12.5.
What is the impact of CVE-2025-13936 on users?
The impact of CVE-2025-13936 can allow an attacker to inject malicious scripts into web pages viewed by users, leading to stored XSS vulnerabilities.
Is there a workaround for CVE-2025-13936?
There is no official workaround for CVE-2025-13936; users are advised to apply the necessary updates to mitigate the risk.