Ransomware Gangs Exploit Critical WatchGuard Firebox Vulnerability
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are exploiting a critical vulnerability in WatchGuard Firebox firewalls.
Tracked as CVE-2025-14733, the flaw is a write-out-of-range vulnerability that can allow an unauthenticated, remote attacker to execute malicious code. The vulnerability requires a low-complexity attack, making exposed and unpatched Firebox devices an attractive target for threat actors.
WatchGuard Firebox devices affected by CVE-2025-14733
The vulnerability affects WatchGuard Firebox appliances running the following Fireware OS versions:
- Fireware OS 11.x and later, including version 11.12.4_Update1
- Fireware OS 12.x and later, including version 12.11.5
- Fireware OS 2025.1 through 2025.1.3
According to WatchGuard’s security advisory for CVE-2025-14733, unpatched Firebox firewalls are vulnerable when configured to use IKEv2 VPN. However, WatchGuard warned that branch office VPN configurations using static gateway peers may remain vulnerable even after the affected configuration is removed.
CISA adds CVE-2025-14733 to its exploited vulnerabilities catalog
In a recent update, CISA added CVE-2025-14733 to its Known Exploited Vulnerabilities (KEV) Catalog. The agency said the vulnerability is being used by ransomware groups, although it did not release details about specific attacks or victims.
The flaw was added to the KEV Catalog in December. Under Binding Operational Directive 22-01, U.S. federal agencies were required to remediate the vulnerability within the specified deadline.
More than 115,000 Firebox firewalls exposed online
Internet security monitoring organization Shadowserver identified more than 115,000 potentially vulnerable WatchGuard Firebox firewalls exposed to the internet in December. Although the number of exposed systems later declined, thousands of potentially vulnerable devices remained visible online months later.

WatchGuard has also published indicators of compromise to help customers determine whether their Firebox devices may have been targeted or compromised.
How to protect WatchGuard Firebox devices
Organizations using affected Firebox appliances should apply the appropriate WatchGuard security update immediately. Administrators should also review IKEv2 and branch office VPN configurations, inspect firewall and VPN logs, and check WatchGuard’s indicators of compromise for signs of unauthorized access.
Internet-exposed management interfaces should be restricted wherever possible, and organizations should verify that all Firebox devices are running a supported, patched version of Fireware OS.
Previous WatchGuard vulnerabilities exploited in attacks
This is not the first WatchGuard vulnerability to be exploited by attackers. In 2022, U.S. cybersecurity agencies ordered government organizations to patch CVE-2022-23176, a flaw affecting WatchGuard Firebox and XTM firewalls.
WatchGuard also addressed another critical remote code execution vulnerability in Firebox appliances, CVE-2025-9242, in September 2025. CISA later added that vulnerability to its exploited vulnerabilities catalog after Shadowserver reported tens of thousands of potentially exposed Firebox devices.
WatchGuard says its products protect more than 250,000 small and medium-sized businesses through a global network of more than 17,000 security resellers and service providers. The widespread use of Firebox appliances makes the rapid remediation of CVE-2025-14733 especially important for businesses and managed service providers.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a two-hour digital summit about AI-powered attacks, modern defense strategies, and how organizations can verify, decide, fix, and revalidate security issues at machine speed.
Source: www.bleepingcomputer.com



