CISA Confirms WatchGuard Firebox RCE Is Being Used in Ransomware Attacks
Vulnerabilities

Illustrative image generated with AI

CISA Confirms WatchGuard Firebox RCE Is Being Used in Ransomware Attacks

CISA confirms critical WatchGuard Firebox RCE CVE-2025-14733 is exploited in ransomware attacks. Learn affected versions, risks, and patch guidance.

Text generated by artificial intelligence, published without human review. AI transparency

The U.S. Cybersecurity and Infrastructure Security Agency has confirmed that ransomware operators are exploiting CVE-2025-14733, a critical remote-code-execution vulnerability in WatchGuard Firebox firewalls.

CISA updated its Known Exploited Vulnerabilities catalog to flag the ransomware activity. The agency has not identified the ransomware groups involved, described the intrusions, or disclosed how many organizations have been compromised.

The vulnerability is not new: CISA added it to the KEV catalog on December 19, 2025, after exploitation had been detected in the wild. However, the ransomware designation establishes that attackers are now using the flaw in financially motivated operations, rather than only scanning for or testing vulnerable appliances.

An unauthenticated path to code execution

CVE-2025-14733 is an out-of-bounds write, classified as CWE-787, in the iked process of WatchGuard Fireware OS. That process handles Internet Key Exchange operations associated with IPsec VPN connections.

A remote attacker can trigger the memory corruption without credentials or user interaction. Successful exploitation permits arbitrary code execution on the firewall, potentially giving an intruder control over a device positioned at the boundary of an organization’s network.

The vulnerability has a CVSS 3.1 score of 9.8 out of 10:

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

That vector reflects a network-accessible attack requiring low complexity, no privileges and no action from a legitimate user. A successful attack can have a high impact on confidentiality, integrity and availability.

WatchGuard also supplied the following CVSS 4.0 vector:

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/U:Red

NIST has not published its own CVSS 4.0 assessment. The NVD entry for CVE-2025-14733 was published on December 19, 2025, and last modified on September 9, 2026.

Exposure depends on IKEv2 configuration—and deleted settings may still matter

Not every Firebox running an affected Fireware release is necessarily exploitable under the documented conditions. The vulnerable device must be configured, or previously have been configured, to use particular IKEv2 VPN modes.

The affected configurations include:

  • Mobile User VPN using IKEv2.
  • Branch Office VPN using IKEv2 with a dynamic gateway peer.
  • Some devices that previously used one of those configurations, even after it was deleted.

The last condition complicates exposure assessments. A Firebox may remain vulnerable after administrators remove the relevant mobile-user or dynamic-peer configuration if a Branch Office VPN to a static gateway peer remains configured.

Consequently, checking only the firewall’s current configuration may produce an incomplete result. Administrators should evaluate configuration history as well as the installed Fireware version, following WatchGuard’s instructions rather than assuming that deleting an IKEv2 profile removed the risk.

The technical characteristics make perimeter appliances attractive targets. Attackers do not need a previously compromised endpoint or valid VPN account, and a successfully exploited firewall can provide a foothold at a highly trusted network location.

Fireware releases and Firebox models affected

The NVD configurations divide affected systems into three principal version ranges and hardware groups.

Fireware versions from 11.10.2 inclusive to 12.5.15 exclusive are affected on:

  • Firebox T15
  • Firebox T35

Versions from 11.10.2 inclusive to 12.11.6 exclusive are affected on:

  • Firebox M270, M290, M370, M390 and M440
  • Firebox M4600, M470, M4800 and M5600
  • Firebox M570, M5800, M590, M670 and M690
  • Firebox NV5
  • Firebox T20, T25, T40, T45, T55, T70, T80 and T85
  • FireboxCloud
  • FireboxV

Fireware versions from 2025.1 inclusive to 2025.1.4 exclusive are affected on:

  • Firebox M295, M395, M495, M595 and M695
  • Firebox T115-W
  • Firebox T125 and T125-W
  • Firebox T145 and T145-W
  • Firebox T185

The NVD software table additionally describes the affected branches as Fireware 2025.1 before 2025.1.4, Fireware 12.0 before 12.11.6, and releases beginning with 11.10.2 through 11.12.4+541730. It also lists separate affected ranges for Fireware 12.0 before 12.3.1+728352 and before 12.5.15.

Because the applicable fixed release depends on the appliance and software branch, operators should match both fields against WatchGuard’s advisory. A single organization may need different upgrade targets across its Firebox estate.

Thousands of vulnerable firewalls remain exposed

WatchGuard issued patches in December 2025, acknowledged active exploitation and published indicators of compromise for customers investigating their appliances.

Shadowserver counted more than 115,000 unpatched Firebox firewalls exposed online in December 2025. Nearly 9,000 remained unsecured as of September 2026. That reduction is substantial, but the remaining population still gives ransomware operators a meaningful pool of potential targets.

The affected customer base may extend beyond organizations that directly manage WatchGuard products. The vendor provides services to more than 250,000 small and medium-sized businesses through over 17,000 resellers and service providers worldwide.

A compromised managed firewall can therefore create operational and incident-response consequences for customers, resellers and managed security providers. CISA has not disclosed whether the confirmed ransomware attacks affected any particular sector or region.

Federal remediation deadline has already passed

CISA placed CVE-2025-14733 in the KEV catalog on December 19, 2025. Under Binding Operational Directive 22-01, U.S. federal civilian agencies had until December 26, 2025, to remediate it.

The required action is explicit: apply the vendor’s mitigations, follow the applicable BOD 22-01 guidance for cloud services, or stop using the product if mitigations are unavailable.

Other organizations are not bound by that federal deadline, but the combination of KEV inclusion, confirmed ransomware exploitation and a remotely reachable attack path warrants urgent handling.

Defenders should:

  1. Inventory physical, virtual and cloud-based Firebox deployments.
  2. Identify the exact appliance model and installed Fireware build.
  3. Upgrade to the appropriate fixed version issued by WatchGuard.
  4. Review both current and previous IKEv2 VPN configurations.
  5. Examine WatchGuard’s published indicators of compromise.
  6. Treat suspicious findings as a possible breach, not merely a patching issue.
  7. Isolate or discontinue appliances that cannot be updated or mitigated.

Patching closes the vulnerability but does not remove persistence or other changes made during an earlier compromise. Devices that were exposed before upgrading require a separate forensic review.

CVE-2025-14733 follows other exploited WatchGuard flaws

This is not WatchGuard’s first recent Firebox vulnerability to enter CISA’s catalog.

CVE-2025-9242 is another 9.8-rated out-of-bounds write in the Fireware iked process. It also permits unauthenticated remote code execution under substantially similar IKEv2 dynamic- and static-peer conditions.

WatchGuard patched CVE-2025-9242 in September 2025. CISA added it to the KEV catalog on November 12, 2025, and set a federal remediation deadline of December 3, 2025. Shadowserver subsequently identified more than 75,000 vulnerable Firebox appliances.

An earlier issue, CVE-2022-23176, affected Firebox and XTM appliances. Unlike the two iked flaws, it required unprivileged credentials and could expose a privileged management session when management access was reachable. CISA added it to KEV on April 11, 2022, with a May 2, 2022 remediation deadline.

For CVE-2025-14733, the immediate priorities are narrower: install the fixed Fireware release, verify historical IKEv2 exposure and investigate for compromise. The ransomware flag means vulnerable appliances should no longer be treated as carrying only a theoretical risk.

Read next

Sources

This article is an original reworking based on the sources below.

CVEs covered in this article

Related topicsWatchGuard FireboxCVE-2025-14733ransomware attacksCISA KEVfirewall RCE vulnerabilityFireware patch
Back to home