#VU119374 XPath injection in Fireware OS - CVE-2025-1545
Published: December 8, 2025
Fireware OS
WatchGuard
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to improper input validation in Web CGI. A remote non-authenticated attacker can send a specially crafted HTTP request to an exposed authentication or management web interface and retrieve sensitive information from the Firebox configuration.