Ransomware gangs are exploiting a critical WatchGuard Firebox firewall vulnerability that can allow unauthenticated attackers to run malicious code remotely, the US Cybersecurity and Infrastructure Security Agency (CISA) has confirmed.
The flaw, tracked as CVE-2025-14733, is caused by an out-of-bounds write and can be exploited in relatively low-complexity attacks. CISA has added it to its catalogue of known exploited vulnerabilities, but has not disclosed which ransomware groups are involved or how the attacks were carried out.
WatchGuard issued patches in December after confirming that the vulnerability was already being exploited. The company said attacks were possible against Firebox devices configured to use IKEv2 virtual private network (VPN) connections.
It warned that removing the affected VPN configuration might not be enough to secure a device if a branch-office VPN connected to a static gateway peer remains in place. WatchGuard also published indicators of compromise to help customers establish whether their firewalls had been breached.
Thousands of vulnerable Firebox devices remain exposed
The vulnerability affects Fireware OS 11.x and later, including version 11.12.4_Update1, 12.x and later, including 12.11.5, and releases from 2025.1 to 2025.1.3.
Internet-monitoring organisation Shadowserver identified more than 115,000 unpatched Firebox firewalls exposed online in December. Almost 9,000 were still unsecured nine months later, leaving them potentially open to attacks exploiting CVE-2025-14733.
CISA first placed the flaw on its Known Exploited Vulnerabilities catalogue in December and directed US federal agencies to address it within a week under Binding Operational Directive 22-01.
The agency has previously warned government organisations about another exploited WatchGuard vulnerability, CVE-2022-23176, which affected Firebox and XTM firewalls.
WatchGuard also fixed a closely related remote-code execution flaw, CVE-2025-9242, in September 2025. CISA listed that vulnerability as actively exploited the following month, after Shadowserver found more than 75,000 vulnerable Firebox devices online.
WatchGuard says its security products are used by more than 250,000 small and medium-sized businesses through a worldwide network of more than 17,000 resellers and service providers.
