CVE-2025-13938: WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Autotask Technology Integration Configuration
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Autotask Technology Integration module) allows Stored XSS.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13938?
CVE-2025-13938 has been classified as a high severity vulnerability due to the potential for stored cross-site scripting (XSS).
How do I fix CVE-2025-13938?
To fix CVE-2025-13938, upgrade your WatchGuard Fireware OS to version 12.11.5 or later.
What versions of Fireware OS are affected by CVE-2025-13938?
CVE-2025-13938 affects WatchGuard Fireware OS versions from 12.4 up to and including 12.11.4, as well as version 12.5 up to and including 12.5.13.
Can CVE-2025-13938 lead to data breaches?
Yes, CVE-2025-13938 can potentially lead to data breaches as it allows attackers to execute malicious scripts in the context of user sessions.
Is there a workaround for CVE-2025-13938 while waiting for a patch?
There is currently no known effective workaround for CVE-2025-13938, so applying the patch promptly is recommended.