CVE-2025-13938: WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Autotask Technology Integration Configuration
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Autotask Technology Integration module) allows Stored XSS.This issue affects Fireware OS 12.4 up to and including 12.11.4, 12.5 up to and including 12.5.13, and 2025.1 up to and including 2025.1.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13938?
CVE-2025-13938 has been classified as a high severity vulnerability due to the potential for stored cross-site scripting (XSS).
How do I fix CVE-2025-13938?
To fix CVE-2025-13938, upgrade your WatchGuard Fireware OS to version 12.11.5 or later.
What versions of Fireware OS are affected by CVE-2025-13938?
CVE-2025-13938 affects WatchGuard Fireware OS versions from 12.4 up to and including 12.11.4, as well as version 12.5 up to and including 12.5.13.
Can CVE-2025-13938 lead to data breaches?
Yes, CVE-2025-13938 can potentially lead to data breaches as it allows attackers to execute malicious scripts in the context of user sessions.
Is there a workaround for CVE-2025-13938 while waiting for a patch?
There is currently no known effective workaround for CVE-2025-13938, so applying the patch promptly is recommended.