ZeroHour
Security Affairspublished ()ingested @securityaffairs

U.S. CISA adds a flaw in WatchGuard Fireware OS to its Known Exploited Vulnerabilities catalog

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-14733
Unauthenticated Out-of-Bounds Write RCE in WatchGuard Fireware OS

CVE-2025-14733 is an out-of-bounds write (CWE-787) in the iked process of WatchGuard Fireware OS on Firebox appliances, allowing a remote, unauthenticated attacker to execute arbitrary code. The flaw is reachable when the appliance is configured for Mobile User VPN with IKEv2 or a branch office VPN (BOVPN) using IKEv2 with a dynamic gateway peer; a Firebox may also remain vulnerable if those IKEv2 configurations were previously set up and then deleted while a BOVPN to a static gateway peer is still configured. Successful exploitation gives an attacker arbitrary code execution on the firewall itself, a high-value network position that can be used for further lateral movement. Affected deployments are WatchGuard Firebox appliances running Fireware OS with the described IKEv2 VPN configurations, since the IKEv2 service by definition listens on the external interface. The vulnerability is under active exploitation: it was added to CISA's KEV catalog on 2025-12-19 with known ransomware use, carries an EPSS probability of 26.5% (98th percentile) of exploitation within 30 days, and no public proof-of-concept is currently known.

Do: Upgrade affected Firebox appliances to the patched Fireware OS builds identified in WatchGuard's security advisory, per CISA KEV required action and applicable BOD 22-01 guidance. Audit configurations for Mobile User VPN with IKEv2 and BOVPN IKEv2 with a dynamic gateway peer, including appliances where those settings were deleted but a BOVPN to a static gateway peer is still configured, as these may remain vulnerable. Until patched, restrict IKEv2 traffic (UDP 500/4500) to trusted source addresses or discontinue use if mitigations are unavailable.

9.327% KEV ransomware
  • WatchGuard Firebox (Fireware OS)
largeplausibly in the tens of thousands of internet-exposed Firebox appliances (order of magnitude 10^4 to 10^5); unknown precisely
CVE-2025-59718
Critical FortiCloud SSO Authentication Bypass in Fortinet FortiOS and FortiProxy

CVE-2025-59718 is a critical (CVSS 9.8) improper verification of cryptographic signature flaw (CWE-347) in the FortiCloud SSO login flow of Fortinet FortiOS, FortiProxy, and FortiSwitchManager, with the Siemens RUGGEDCOM APE1808 appliance also listed in the CVE's affected CPE entries. An unauthenticated attacker who can reach a device's FortiCloud SSO login can submit a crafted SAML response message whose cryptographic signature is not properly verified, bypassing authentication entirely. The bypass grants unauthorized access to the affected device with high impact on confidentiality, integrity, and availability, typically administrative control of the management interface. Any organization running the affected FortiOS 7.0–7.6, FortiProxy 7.0–7.6, or FortiSwitchManager 7.0–7.2 versions that uses FortiCloud SSO for administrative login is exposed. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-12-16, security reporting describes active attacks against FortiGate firewalls via this SAML SSO bypass, and EPSS assigns a 68.3% probability of exploitation within 30 days.

Do: Upgrade all affected products out of the vulnerable ranges — FortiOS beyond 7.6.3/7.4.8/7.2.11/7.0.17, FortiProxy beyond 7.6.3/7.4.10/7.2.14/7.0.21, and FortiSwitchManager beyond 7.2.6/7.0.5 — using the fixed builds listed in Fortinet's security advisory, and patch Siemens RUGGEDCOM APE1808 firmware per Siemens guidance. As interim mitigation, disable or restrict FortiCloud SSO-based administrative login, limit management-interface exposure to trusted networks, and review admin/SSO logs for anomalous sign-ins or forged SAML responses. Given the KEV listing, US federal agencies must apply vendor mitigations or discontinue use of affected products per BOD 22-01.

9.868% KEV
  • Fortinet FortiOS 7.0.0-7.0.17, 7.2.0-7.2.11, 7.4.0-7.4.8, 7.6.0-7.6.3
  • Fortinet FortiProxy 7.0.0-7.0.21, 7.2.0-7.2.14, 7.4.0-7.4.10, 7.6.0-7.6.3
  • Fortinet FortiSwitchManager 7.0.0-7.0.5, 7.2.0-7.2.6
  • +1 more
masslikely on the order of 100,000+ internet-exposed FortiOS/FortiProxy systems (Fortinet's deployed base is in the millions); the directly exploitable set is the…
CVE-2025-59719
Unauthenticated SAML Signature Bypass in Fortinet FortiWeb (FortiCloud SSO)

FortiWeb contains an improper verification of cryptographic signature (CWE-347) in its FortiCloud SSO login flow, allowing an unauthenticated attacker to bypass authentication by submitting a crafted SAML response whose signature is not properly validated. Because this requires no privileges or user interaction and is network-reachable, successful exploitation grants the attacker the access of a legitimate SSO-authenticated administrator to the appliance's management interface. The flaw affects FortiWeb 8.0.0, 7.6.0 through 7.6.4, and 7.4.0 through 7.4.9. Organizations running these versions are affected, particularly where the management interface is reachable and FortiCloud SSO login is enabled. As of this analysis the flaw is not in the CISA KEV catalog and no public proof-of-concept is known, but a closely related SAML SSO authentication bypass in FortiGate firewalls (CVE-2025-59718) is under active attack and Fortinet has issued urgent authentication patches, so elevated exploitation risk is plausible.

Do: Upgrade FortiWeb to a patched release per Fortinet's PSIRT advisory covering CVE-2025-59719, prioritizing internet-facing appliances on 8.0.0, 7.6.x, or 7.4.x. As interim mitigation, restrict access to the management interface, disable or limit FortiCloud SSO login in favor of local or hardened admin authentication, and review SSO login logs for successful authentications from unexpected sources. Note that the sibling FortiGate SAML bypass (CVE-2025-59718) is being actively exploited, so treat this patch as urgent.

9.829%
  • fortinet fortiweb 8.0.0
  • fortinet fortiweb 7.6.0 through 7.6.4
  • fortinet fortiweb 7.4.0 through 7.4.9
largetens of thousands of internet-exposed FortiWeb appliances (order of magnitude ~10k-100k), with the exploitable subset limited to deployments using FortiCloud…
CVE-2025-9242
Out-of-Bounds Write in WatchGuard Fireware OS iked Enables Unauthenticated RCE

WatchGuard Fireware OS contains an out-of-bounds write (CWE-787) in the iked process that a remote, unauthenticated attacker can trigger to execute arbitrary code on the appliance. The flaw is reachable via the mobile user VPN with IKEv2 and via branch office VPNs using IKEv2 to a dynamic gateway peer; devices whose IKEv2 configurations were deleted may remain vulnerable if a branch office VPN to a static gateway peer is still configured. Successful exploitation yields full system compromise, reflected in the CVSS v4.0 base score of 9.3 (network vector, no privileges or user interaction, high impact on confidentiality, integrity and availability). WatchGuard Firebox appliances with IKEv2 VPN services are affected, with public reporting citing roughly 54,000 internet-exposed Fireboxes; the issue was added to CISA's Known Exploited Vulnerabilities catalog on 2025-11-12, a public proof-of-concept exploit exists, and headlines indicate use in ransomware attacks (KEV ransomware field is listed as unknown). EPSS assigns a 91.3% probability of exploitation within 30 days (100th percentile), so remediation urgency is high.

Do: Apply the patched Fireware OS release per WatchGuard's security advisory immediately (exact fixed version numbers are not provided in the source data); the KEV listing makes BOD 22-01 remediation timelines mandatory for U.S. federal agencies. As an interim mitigation, restrict or disable IKEv2 VPN exposure — mobile user VPN with IKEv2 and branch office VPN IKEv2, including residual static-peer BOVPN configurations on devices that previously had IKEv2 configured — to trusted sources only. Administrators should audit configuration history to identify Fireboxes with prior IKEv2 mobile VPN or dynamic-peer BOVPN setups, since these may remain vulnerable even after the configs were deleted.

9.391% KEV PoC
  • WatchGuard Firebox appliances running Fireware OS (iked process)
large≈54,000 internet-exposed Fireboxes (public scan figure cited in coverage)
Full article880 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini December 20, 2025

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a WatchGuard Fireware OS flaw to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a WatchGuard Firebox OS vulnerability, tracked as CVE-2025-14733 (CVSS Score of 9.3), to its Known Exploited Vulnerabilities (KEV) catalog.

This flaw is a critical out-of-bounds write vulnerability in WatchGuard Fireware OS that can be exploited remotely and without authentication.

When IKEv2 VPN services (Mobile User VPN or Branch Office VPN) are configured with a dynamic gateway peer, specially crafted network traffic can trigger improper memory handling. As a result, an attacker can write data outside the intended memory bounds, potentially leading to arbitrary code execution on the affected device.

The vulnerability impacts multiple Fireware OS branches, including versions 11.10.2–11.12.4_Update1, 12.0–12.11.5, and 2025.1–2025.1.3, putting exposed VPN gateways at high risk of full compromise.

“An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer,” reads the advisory published by WatchGuard.

“If the Firebox was previously configured with the mobile user VPN with IKEv2 or a branch office VPN using IKEv2 to a dynamic gateway peer, and both of those configurations have since been deleted, that Firebox may still be vulnerable if a branch office VPN to a static gateway peer is still configured.”

WatchGuard has released detailed Indicators of Attack (IoAs) and mitigation guidance to help customers detect and reduce the risk of exploitation of this vulnerability.

WatchGuard identified several signals that may indicate exploitation attempts or compromise on vulnerable Firebox appliances:

  • Suspicious IP addresses: Outbound connections to known malicious IPs (e.g., 45.95.19[.]50, 51.15.17[.]89, 172.93.107[.]67, 199.247.7[.]82) are strong indicators of compromise. Inbound traffic from these IPs may indicate scanning or exploit attempts.
  • Log anomalies:
    • Errors indicating an invalid or unusually long peer certificate chain (more than 8 certificates) in IKEv2 authentication are a medium-confidence attack indicator.
    • IKE_AUTH requests with abnormally large CERT payloads (over 2000 bytes) are considered a strong indicator of exploitation attempts.
  • Abnormal device behavior:
    • An IKED process hang, disrupting VPN negotiations and re-keying, is a strong sign of a successful exploit.
    • An IKED process crash and fault report may also occur, though this is a weaker indicator as crashes can have other causes.

Administrators who detect suspicious activity are advised to rotate all locally stored secrets on affected Firebox devices after updating.

If immediate patching is not possible, and the Firebox is only using Branch Office VPNs with static gateway peers, the vendor recommends temporarily following its best practices for securing IPSec/IKEv2 Branch Office VPNs. This workaround reduces exposure but does not replace the need to install the official fix as soon as possible.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the vulnerabilities by December 26, 2025.

The HackerNews noted that the IP address “199.247.7[.]82” that is listed in the advisory was also flagged by cybersecurity firm Arctic Wolf earlier this week as linked to the exploitation of two recently disclosed flaws in Fortinet FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager (CVE-2025-59718 and CVE-2025-59719, CVSS scores: 9.8).

In November, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added another WatchGuard Firebox flaw, tracked as CVE-2025-9242, to the Kev catalog.

In mid-October, researchers revealed details of the critical vulnerability CVE-2025-9242 (CVSS score of 9.3) in WatchGuard Fireware. An unauthenticated attacker can exploit the flaw to execute arbitrary code. The vulnerability is an out-of-bounds write issue that affects Fireware OS versions 11.10.2–11.12.4_Update1, 12.0–12.11.3, and 2025.1.

“An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the Mobile User VPN with IKEv2 and the Branch Office VPN using IKEv2 when configured with a dynamic gateway peer.” reads the advisory. “This vulnerability affects Fireware OS 11.10.2 up to and including 11.12.4_Update1, 12.0 up to and including 12.11.3 and 2025.1.”

The vendor states that a WatchGuard Fireware OS iked process flaw allows remote unauthenticated attackers to execute arbitrary code via an out-of-bounds write vulnerability. The vulnerability impacts Firebox devices using IKEv2 for mobile user or branch office VPNs with dynamic gateways. The company pointed out that even if those VPNs were deleted, devices remain at risk if a branch office VPN to a static gateway is still configured.

The flaw lets unauthenticated attackers execute arbitrary code on a perimeter appliance by targeting the IKEv2 VPN service, an Internet-exposed entry point, making the bug reachable before authentication, as per watchTowr researchers.

This vulnerability ticks all the boxes ransomware actors crave: remote code execution on a perimeter device, exposure via a public-facing VPN service, and pre-auth exploitability, making it a high-priority target for exploitation and urgent to patch.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/185896/hacking/u-s-cisa-adds-a-flaw-in-watchguard-fireware-os-to-its-known-exploited-vulnerabilities-catalog.html