Vulnerability Description
A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the Access Portal configuration. An authenticated remote attacker with administrator privileges could exploit this vulnerability to execute arbitrary JavaScript code in the Firebox management interface of another management user.
Related Weaknesses (CWE)
References
- https://psirt.watchguard.com/CVE-2025-4805
- https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2025-00007
FAQ
What is CVE-2025-4805?
CVE-2025-4805 is a documented vulnerability. A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the Access Portal configuration. An authenticated remote attacker with adminis...
How severe is CVE-2025-4805?
CVSS scoring is not yet available for CVE-2025-4805. Check NVD for updates.
Is there a patch for CVE-2025-4805?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.