The U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed that ransomware gangs are currently exploiting the critical CVE-2025-14733 vulnerability in WatchGuard Firebox firewalls. The agency added the vulnerability to its Known Exploited Vulnerabilities catalog in December, but later clarified in an update that its use by ransomware gangs is now known, without publishing additional details about the attacks.
The vulnerability results from an out-of-bounds write operation and can be exploited by an unauthenticated attacker to remotely execute malicious code. According to WatchGuard's description, exploitation does not require a high level of complexity, increasing the importance of addressing affected devices, particularly because they operate at network boundaries and provide a potential entry point into enterprise environments.
Affected Versions and Exploitation Conditions
The list of affected systems includes Firebox firewalls running the following versions of Fireware OS:
- Version 11.x, including 11.12.4_Update1.
- Version 12.x or later, including 12.11.5.
- Versions from 2025.1 through 2025.1.3.
When it released the security patches in December, WatchGuard said that unupdated devices were vulnerable to attack when configured to use IKEv2 VPNs. It also warned that deleting the affected settings might not be sufficient in some cases if a branch VPN connection remained configured with a static gateway peer. At the time, the company confirmed that exploitation was occurring in the wild and provided indicators of compromise to help customers determine whether their devices had been compromised.
Why Does This Matter?
The importance of the update is not limited to the existence of a remote code execution vulnerability, but also extends to its transition into the context of ransomware attacks. This means that network administrators who postpone updating Firebox firewalls face not merely a theoretical possibility of compromise, but a risk associated with known criminal activity, although CISA has not disclosed the nature of the campaigns, the responsible groups, or the extent of the damage.
The internet security monitoring organization Shadowserver found that more than 115,000 unupdated Firebox firewalls were exposed on the internet in December, while approximately 9,000 devices remained unsecured nine months later. This indicates that an exploitable attack surface remains, despite the passage of months since patches became available.
What Should Be Reviewed in Practice?
Organizations using Firebox should verify the Fireware OS version, apply the appropriate patches, and review IKEv2 settings and VPN connections between branches and static gateways. Using the indicators of compromise published by WatchGuard is also useful for inspecting devices rather than merely installing the update, because the company warned that some devices could have been compromised before the settings were removed or remediation was applied.
This case is part of a series of vulnerabilities exploited in WatchGuard products. Two years ago, CISA ordered U.S. government agencies to address another vulnerability, CVE-2022-23176, in Firebox and XTM firewalls. In September 2025, WatchGuard fixed a nearly similar remote code execution vulnerability, CVE-2025-9242, which CISA later added to its Known Exploited Vulnerabilities catalog. The source does not establish that the two vulnerabilities are being used in the same current campaigns, but it illustrates the continued exposure of this category of devices to active targeting.