Executive brief
WatchGuard Firebox is a network firewall appliance used to protect corporate networks and control internet access. An XPath injection vulnerability in its web-based administration interface allows unauthenticated remote attackers to extract sensitive configuration data from systems with authentication hotspots enabled, potentially exposing credentials, network topology, and security policies.
Technical details
The vulnerability is an XPath injection (CWE-91) in the web CGI components of WatchGuard Fireware OS. It affects systems with at least one authentication hotspot configured, allowing an unauthenticated attacker to query the Firebox configuration via the exposed management web interface. The attack requires network access to the management interface but no authentication credentials. Successful exploitation permits information disclosure of sensitive configuration data. Patches are available: Fireware OS 2025.1.3, 12.11.5, and 12.5.14 or later versions.
Affected products
- WatchGuard Fireware OS 2025.1.x before 2025.1.3; 12.0.x through 12.11.4; 11.11.x through 11.12.4+541730; T15/T35 12.0.x before 12.5.14
Timeline
- 2025-12-04: disclosed