CVE-2025-13937: WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in ConnectWise Technology Integration Configuration
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (ConnectWise Technology Integration module) allows Stored XSS.This issue affects Fireware OS 12.4 up to and including 12.11.4, 12.5 up to and including 12.5.13, and 2025.1 up to and including 2025.1.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13937?
CVE-2025-13937 has a high severity rating due to its potential for stored cross-site scripting (XSS) attacks.
How do I fix CVE-2025-13937?
To fix CVE-2025-13937, update WatchGuard Fireware OS to the latest version that addresses this vulnerability.
What systems are affected by CVE-2025-13937?
CVE-2025-13937 affects WatchGuard Fireware OS versions from 12.4 up to 12.11.4 and specific 12.5 versions.
What should I do if I can't update to a fixed version for CVE-2025-13937?
If unable to update, implement additional input validation measures to mitigate the risk of XSS attacks until an update can be performed.
Can CVE-2025-13937 be exploited remotely?
Yes, CVE-2025-13937 can be exploited remotely by attackers to execute malicious scripts within affected web pages.