The U.S. Cybersecurity and Infrastructure Security Agency (CISA) says ransomware gangs are exploiting a critical vulnerability in WatchGuard Firebox firewalls.
Tracked as CVE-2025-14733, the flaw involves an out-of-bounds write that allows unauthenticated threat actors to execute malicious code remotely in low-complexity attacks. It affects devices running Fireware OS 11.x and later, including 11.12.4_Update1, 12.x and later, including 12.11.5, and versions from 2025.1 through 2025.1.3.
When WatchGuard released patches in December, it said attacks were possible only when a Firebox was configured to use IKEv2 VPN. However, the company warned that devices could remain compromised after vulnerable configurations were deleted if a branch office VPN to a static gateway peer was still configured. WatchGuard also shared indicators of compromise.
Shadowserver found that nearly 9,000 Firebox instances remained unsecured after nine months. CISA added CVE-2025-14733 to its Known Exploited Vulnerabilities (KEV) catalog in December and ordered U.S. federal agencies to secure affected systems within a week under Binding Operational Directive (BOD) 22-01. CISA said the flaw is now used by ransomware gangs but provided no further attack details.
Comments
0No comments yet. Be the first to comment.