WatchGuard Firebox XPath Injection Vulnerability in Web CGI
Summary
| CVE | CVE-2025-1545 |
|---|---|
| State | PUBLISHED |
| Assigner | WatchGuard |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2025-12-04 22:15:48 UTC |
| Updated | 2026-08-10 16:19:14 UTC |
| Description | An XPath Injection vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to retrieve sensitive information from the Firebox configuration through an exposed authentication or management web interface. This vulnerability only affects Firebox systems that have at least one authentication hotspot configured. |
Risk And Classification
Primary CVSS: v4.0 8.2 HIGH from 5d1c2695-1a31-4499-88ae-e847036fd7e3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Problem Types: CWE-91 | CWE-91 CWE-91
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | 5d1c2695-1a31-4499-88ae-e847036fd7e3 | Secondary | 8.2 | HIGH | CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/C... |
| 4.0 | CNA | DECLARED | 8.2 | HIGH | CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
| 3.1 | [email protected] | Primary | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
CVSS v4.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowAttack Requirements
PresentPrivileges Required
NoneUser Interaction
NoneConfidentiality
HighIntegrity
NoneAvailability
NoneSub Conf.
NoneSub Integrity
NoneSub Availability
NoneCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
NoneAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Watchguard | Firebox T115-w | - | All | All | All |
| Hardware | Watchguard | Firebox T125 | - | All | All | All |
| Hardware | Watchguard | Firebox T125-w | - | All | All | All |
| Hardware | Watchguard | Firebox T145 | - | All | All | All |
| Hardware | Watchguard | Firebox T145-w | - | All | All | All |
| Hardware | Watchguard | Firebox T185 | - | All | All | All |
| Operating System | Watchguard | Fireware | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | WatchGuard | Fireware OS | affected 2025.1 2025.1.3 custom | Default |
| CNA | WatchGuard | Fireware OS | affected 12.0 12.11.5 custom | Default |
| CNA | WatchGuard | Fireware OS | affected 11.11 11.12.4+541730 custom | Default |
| CNA | WatchGuard | Fireware OS | affected 12.0 12.5.14 custom | T15/T35 |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| psirt.watchguard.com/CVE-2025-1545 | 5d1c2695-1a31-4499-88ae-e847036fd7e3 | psirt.watchguard.com | |
| www.watchguard.com/wgrd-psirt/advisory/wgsa-2025-00025 | 5d1c2695-1a31-4499-88ae-e847036fd7e3 | www.watchguard.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Exodus Intelligence (en)
Additional Advisory Data
Solutions
CNA: Fireware OS 2025.1.3, Fireware OS 12.11.5, Fireware OS 12.5.14
Exploits
CNA: WatchGuard is not aware of any exploitation of this vulnerability in the wild.
There are currently no legacy QID mappings associated with this CVE.