Skip to content
Tech News
← Back to articles

CISA: WatchGuard RCE flaw now exploited in ransomware attacks

read original get WatchGuard Firebox T25 Firewall Appliance → more articles
Why This Matters

A critical, easily exploitable RCE bug in WatchGuard Firebox firewalls (CVE-2025-14733) has escalated from targeted exploitation to use by ransomware gangs, per CISA. Edge security appliances remain a favored ransomware entry point, and thousands of unpatched devices are still exposed months after patches shipped.

Key Takeaways
Worth a Look

WatchGuard Firebox T25 Firewall Appliance — If you're running an older Firebox that's overdue for a refresh, the Firebox T25 is WatchGuard's current small-office appliance and runs the modern Fireware releases that receive active security updates. It's a straightforward way to get a supported, patchable edge device with VPN and unified threat management in one box.

See WatchGuard Firebox T25 Firewall Appliance on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a critical WatchGuard Firebox firewall vulnerability, which it flagged as actively exploited in December.

This flaw is tracked as CVE-2025-14733 and stems from an out-of-bounds write allowing unauthenticated threat actors to execute malicious code remotely in low-complexity attacks.

This vulnerability affects firewalls running Fireware OS 11.x and later (including 11.12.4_Update1), 12.x or later (including 12.11.5), and 2025.1 through 2025.1.3.

When it released CVE-2025-14733 security patches in December, WatchGuard said unpatched Firebox firewalls are vulnerable to attacks only if configured to use IKEv2 VPN, but noted they might still be compromised even if the vulnerable configurations have been deleted if a branch office VPN to a static gateway peer is still configured.

WatchGuard also confirmed that attackers were exploiting the flaw in the wild and shared indicators of compromise to help customers check whether their Firebox devices have been hacked.

Internet security watchdog group Shadowserver found over 115,00 unpatched Firebox firewalls exposed online in December, and nearly 9,000 instances remain unsecured after nine months.

Vulnerable WatchGuard firewalls exposed online (Shadowserver)

In a Thursday update to its catalog of actively exploited vulnerabilities, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) said the CVE-2025-14733 flaw is now known to be used by ransomware gangs but has not provided more details about their attacks.

CISA first added the flaw to its Known Exploited Vulnerabilities (KEV) catalog in December, when it ordered U.S. federal agencies to secure their systems within a week, as mandated by Binding Operational Directive (BOD) 22-01.

Two years ago, the cybersecurity agency ordered government agencies to patch another actively exploited WatchGuard flaw (CVE-2022-23176) affecting Firebox and XTM firewalls.

... continue reading