MEDIUM · 6.1

CVE-2025-13939

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Gateway Wireless Controller module) allows Stored XSS.This issue af...

Vulnerability Description

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Gateway Wireless Controller module) allows Stored XSS.This issue affects Fireware OS 11.7.2 up to and including 11.12.4+541730, 12.0 up to and including 12.11.4, 12.5 up to and including 12.5.13, and 2025.1 up to and including 2025.1.2.

CVSS Score

6.1

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
WatchguardFireware>= 2025.1, < 2025.1.3
WatchguardFirebox T115-W-
WatchguardFirebox T125-
WatchguardFirebox T125-W-
WatchguardFirebox T145-
WatchguardFirebox T145-W-
WatchguardFirebox T185-
WatchguardFirebox M270-
WatchguardFirebox M290-
WatchguardFirebox M370-
WatchguardFirebox M390-
WatchguardFirebox M440-
WatchguardFirebox M4600-
WatchguardFirebox M470-
WatchguardFirebox M4800-
WatchguardFirebox M5600-
WatchguardFirebox M570-
WatchguardFirebox M5800-
WatchguardFirebox M590-
WatchguardFirebox M670-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-13939?

CVE-2025-13939 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS (Gateway Wireless Controller module) allows Stored XSS.This issue af...

How severe is CVE-2025-13939?

CVE-2025-13939 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2025-13939?

Check the references section above for vendor advisories and patch information. Affected products include: Watchguard Fireware, Watchguard Firebox T115-W, Watchguard Firebox T125, Watchguard Firebox T125-W, Watchguard Firebox T145.