CVE-2025-4805: WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Acces Portal Configuration
A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the Access Portal configuration. An authenticated remote attacker with administrator privileges could exploit this vulnerability to execute arbitrary JavaScript code in the Firebox management interface of another management user.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WatchGuard Firebox Fireware OSto a version that resolves this vulnerability.Fixed in 12.11.2 - Compensating control
Mitigate the stored XSS exposure by limiting administrator access to the Firebox management interface (including access to the Access Portal configuration) to trusted users and sources only.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4805?
CVE-2025-4805 is classified as a high severity vulnerability due to its potential for stored cross-site scripting (XSS) attacks.
How do I fix CVE-2025-4805?
To mitigate CVE-2025-4805, update your WatchGuard Fireware OS to a version that is not vulnerable, specifically above version 12.11.1.
Who is affected by CVE-2025-4805?
CVE-2025-4805 affects authenticated administrators using WatchGuard Fireware OS versions 12.0 to 12.11.1.
What type of vulnerability is CVE-2025-4805?
CVE-2025-4805 is categorized as an improper neutralization of input leading to stored cross-site scripting (XSS) vulnerability.
Is user authentication required for CVE-2025-4805 exploitation?
Yes, CVE-2025-4805 requires an authenticated administrator session to exploit this stored XSS vulnerability.