CVE-2025-13939: WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Gateway Wireless Controller
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Gateway Wireless Controller module) allows Stored XSS.This issue affects Fireware OS 11.7.2 up to and including 11.12.4+541730, 12.0 up to and including 12.11.4, 12.5 up to and including 12.5.13, and 2025.1 up to and including 2025.1.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13939?
CVE-2025-13939 has been rated as a critical severity vulnerability due to the potential for stored XSS attacks.
How do I fix CVE-2025-13939?
To fix CVE-2025-13939, update WatchGuard Fireware OS to version 11.12.5 or later or 12.5.14 or later, depending on your existing version.
What systems are affected by CVE-2025-13939?
CVE-2025-13939 affects Fireware OS versions from 11.7.2 up to 11.12.4 and from 12.0 up to 12.5.13.
What type of vulnerability is CVE-2025-13939?
CVE-2025-13939 is characterized as an improper neutralization of input leading to cross-site scripting (XSS) vulnerabilities.
Is CVE-2025-13939 a remote exploit?
Yes, CVE-2025-13939 can be exploited remotely, making it particularly dangerous for web applications.