CVE-2026-3343 PUBLISHED

WatchGuard Firebox Reflected Cross-Site-Scripting (XSS) Vulnerability in Fireware Web UI

Assigner: WatchGuard
Reserved: 27.02.2026 Published: 03.03.2026 Updated: 03.03.2026

A reflected cross-site scripting (XSS) vulnerability in the Fireware OS Web UI enabled execution of malicious JavaScript in the context of an authenticated management user's browser when they click on a specially crafted link.

This vulnerability affects Fireware OS 12.7 up to and including 12.11.7 and 2025.1 up to and including 2026.1.1.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CVSS Score: 5.1

Product Status

Vendor WatchGuard
Product Fireware OS
Versions Default: unaffected
  • affected from 12.7 to 12.11.7 (incl.)
  • affected from 2025.1 to 2026.1.1 (incl.)

Exploits

WatchGuard is not aware of any exploitation of this issue in the wild.

Credits

  • btaol finder

References

Problem Types

  • CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') CWE

Impacts

  • CAPEC-591 Reflected XSS