ZeroHour
Product

Firebox

1 mentions in 7 days · 1 in 30 days · 1 total · first seen · last

Timeline

CISA: WatchGuard RCE flaw now exploited in ransomware attacks

CISA confirms ransomware gangs are exploiting critical unauthenticated RCE CVE-2025-14733 in WatchGuard Firebox firewalls, with roughly 9,000 devices still unpatched.

CVE-2025-14733 is an out-of-bounds write in WatchGuard Fireware OS allowing unauthenticated remote code execution, exploitable on firewalls configured for IKEv2 VPN and potentially even after the configuration was deleted if a static branch-office VPN peer remains. WatchGuard released patches in December and confirmed in-the-wild exploitation; Shadowserver found over 115,000 exposed Fireboxes at the time, with nearly 9,000 still unpatched after nine months. CISA added the flaw to its Known Exploited Vulnerabilities catalog in December under BOD 22-01 and on Thursday confirmed ransomware gangs are now exploiting it, without providing campaign details. WatchGuard serves more than 250,000 small and mid-sized companies through 17,000+ security resellers and service providers.

Related CVEs

  • Out-of-Bounds Write in WatchGuard Fireware OS iked Enables Unauthenticated RCE
    WatchGuard Fireware OS contains an out-of-bounds write (CWE-787) in the iked process that a remote, unauthenticated attacker can trigger to execute arbitrary code on the appliance. The flaw is reachable via the mobile user VPN with IKEv2 and via branch office VPNs using IKEv2 to a dynamic gateway peer; devices whose IKEv2 configurations were deleted may remain vulnerable if a branch office VPN to a static gateway peer is still configured. Successful exploitation yields full system compromise, reflected in the CVSS v4.0 base score of 9.3 (network vector, no privileges or user interaction, high impact on confidentiality, integrity and availability). WatchGuard Firebox appliances with IKEv2 VPN services are affected, with public reporting citing roughly 54,000 internet-exposed Fireboxes; the issue was added to CISA's Known Exploited Vulnerabilities catalog on 2025-11-12, a public proof-of-concept exploit exists, and headlines indicate use in ransomware attacks (KEV ransomware field is listed as unknown). EPSS assigns a 91.3% probability of exploitation within 30 days (100th percentile), so remediation urgency is high.
    · WatchGuard Firebox appliances running Fireware OS (iked process) KEV PoC large
  • Unauthenticated Out-of-Bounds Write RCE in WatchGuard Fireware OS
    CVE-2025-14733 is an out-of-bounds write (CWE-787) in the iked process of WatchGuard Fireware OS on Firebox appliances, allowing a remote, unauthenticated attacker to execute arbitrary code. The flaw is reachable when the appliance is configured for Mobile User VPN with IKEv2 or a branch office VPN (BOVPN) using IKEv2 with a dynamic gateway peer; a Firebox may also remain vulnerable if those IKEv2 configurations were previously set up and then deleted while a BOVPN to a static gateway peer is still configured. Successful exploitation gives an attacker arbitrary code execution on the firewall itself, a high-value network position that can be used for further lateral movement. Affected deployments are WatchGuard Firebox appliances running Fireware OS with the described IKEv2 VPN configurations, since the IKEv2 service by definition listens on the external interface. The vulnerability is under active exploitation: it was added to CISA's KEV catalog on 2025-12-19 with known ransomware use, carries an EPSS probability of 26.5% (98th percentile) of exploitation within 30 days, and no public proof-of-concept is currently known.
    · WatchGuard Firebox (Fireware OS) KEV ransomwarelarge
  • Privilege Escalation in WatchGuard Firebox/XTM Fireware OS
    WatchGuard Firebox and XTM appliances running affected versions of Fireware OS contain a privilege escalation flaw that allows a remote attacker who already holds unprivileged credentials to obtain a privileged management session via exposed management access. The flaw is triggered when management access is exposed (for example, to the internet) and an attacker authenticates with low-privileged credentials, at which point they can elevate to privileged management of the appliance. Because the CVSS v3.1 score of 8.8 carries high confidentiality, integrity, and availability impact, full compromise of the appliance is the realistic outcome. Organizations running Fireware OS before 12.7.2_U1, 12.x before 12.1.3_U3, or 12.2.x through 12.5.x before 12.5.7_U3 are affected. The vulnerability is being exploited in the wild: CISA added it to the Known Exploited Vulnerabilities Catalog on 2022-04-11, and the Russia-linked Cyclops Blink botnet used it as an initial access vector to infect thousands of devices before the FBI disrupted the botnet.
    · WatchGuard Firebox and XTM appliances (Fireware OS) Fireware OS before 12.7.2_U1; 12.x before 12.1.3_U3; 12.2.x through 12.5.x before 12.5.7_U3 KEVmass

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.