---
id: CVE-2025-1545
title: >-
  An XPath Injection vulnerability in WatchGuard Fireware OS may allow a remote
  unauthenticated attacker to retrieve sensitive information from the Firebox
  configuration through an exposed authentication or management web interface
summary: >-
  An XPath Injection vulnerability in WatchGuard Fireware OS may allow a remote
  unauthenticated attacker to retrieve sensitive information from the Firebox
  configuration through an exposed authentication or management web interface.
  This v…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-91
vendor: watchguard
product: fireware
affected:
  - 'fireware >= 2025.1, < 2025.1.3'
  - 'fireware >= 11.11, < 12.11.5'
  - 'fireware >= 11.11, < 12.5.14'
patched:
  - fireware 12.5.14
published: '2025-12-04'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T23:10:00.463'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-1545'
references:
  - url: 'https://psirt.watchguard.com/CVE-2025-1545'
    label: 5d1c2695-1a31-4499-88ae-e847036fd7e3
  - url: 'https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2025-00025'
    label: 5d1c2695-1a31-4499-88ae-e847036fd7e3
tags:
  - nvd
epss: 0.00479
epssPercentile: 0.3873
ingestedAt: '2026-09-25T23:21:16.882Z'
---

## Overview

An XPath Injection vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to retrieve sensitive information from the Firebox configuration through an exposed authentication or management web interface. This vulnerability only affects Firebox systems that have at least one authentication hotspot configured.

## Affected

- `fireware >= 2025.1, < 2025.1.3`
- `fireware >= 11.11, < 12.11.5`
- `fireware >= 11.11, < 12.5.14`

## Remediation

Upgrade past the affected range:

- `fireware 12.5.14`
