ZeroHour

CVE-2022-23176

KEVmass

Privilege Escalation in WatchGuard Firebox/XTM Fireware OS

CISA: WatchGuard Firebox and XTM Privilege Escalation Vulnerability

CVSS 3.1
8.8 high
EPSS
13%p96
Published
()
KEV added
AI analysis

WatchGuard Firebox and XTM appliances running affected versions of Fireware OS contain a privilege escalation flaw that allows a remote attacker who already holds unprivileged credentials to obtain a privileged management session via exposed management access. The flaw is triggered when management access is exposed (for example, to the internet) and an attacker authenticates with low-privileged credentials, at which point they can elevate to privileged management of the appliance. Because the CVSS v3.1 score of 8.8 carries high confidentiality, integrity, and availability impact, full compromise of the appliance is the realistic outcome. Organizations running Fireware OS before 12.7.2_U1, 12.x before 12.1.3_U3, or 12.2.x through 12.5.x before 12.5.7_U3 are affected. The vulnerability is being exploited in the wild: CISA added it to the Known Exploited Vulnerabilities Catalog on 2022-04-11, and the Russia-linked Cyclops Blink botnet used it as an initial access vector to infect thousands of devices before the FBI disrupted the botnet.

What to do: Upgrade affected Fireware OS branches to 12.7.2_U1, 12.1.3_U3, or 12.5.7_U3 (or later) per WatchGuard's instructions, as required by CISA's KEV catalog. Until patched, restrict appliance management access to trusted networks or management VPNs rather than exposing it to the internet. Because this flaw was used to deploy the Cyclops Blink botnet, administrators should also check Firebox/XTM devices for signs of that compromise using vendor detection guidance.

Affected
WatchGuard Firebox and XTM appliances (Fireware OS)Fireware OS before 12.7.2_U1; 12.x before 12.1.3_U3; 12.2.x through 12.5.x before 12.5.7_U3
Estimated exposure
masson the order of 100,000+ potentially exposed Firebox/XTM appliances (WatchGuard's installed base is cited in the millions, with management access commonly… — WatchGuard Firebox/XTM appliances are widely deployed as SMB and enterprise edge firewalls, and the Cyclops Blink botnet's infection of thousands of devices demonstrates that exposed management access on this platform is common, so the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

WatchGuard Firebox and XTM appliances allow a remote attacker with unprivileged credentials to access the system with a privileged management session via exposed management access. This vulnerability impacts Fireware OS before 12.7.2_U1, 12.x before 12.1.3_U3, and 12.2.x through 12.5.x before 12.5.7_U3.

CISA Known Exploited Vulnerability
Affected
WatchGuard Firebox and XTM
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
watchguard
Products
fireware
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

CISA: WatchGuard RCE flaw now exploited in ransomware attacks

CISA confirms ransomware gangs are exploiting critical unauthenticated RCE CVE-2025-14733 in WatchGuard Firebox firewalls, with roughly 9,000 devices still unpatched.

CVE-2025-14733 is an out-of-bounds write in WatchGuard Fireware OS allowing unauthenticated remote code execution, exploitable on firewalls configured for IKEv2 VPN and potentially even after the configuration was deleted if a static branch-office VPN peer remains. WatchGuard released patches in December and confirmed in-the-wild exploitation; Shadowserver found over 115,000 exposed Fireboxes at the time, with nearly 9,000 still unpatched after nine months. CISA added the flaw to its Known Exploited Vulnerabilities catalog in December under BOD 22-01 and on Thursday confirmed ransomware gangs are now exploiting it, without providing campaign details. WatchGuard serves more than 250,000 small and mid-sized companies through 17,000+ security resellers and service providers.