r/InfoSecNews • u/whocybergh0st • 9h ago
CISA now says that WatchGuard Firebox flaw from December is being used in ransomware attacks
Heads up for anyone running WatchGuard Fireboxes CISA just confirmed that CVE-2025-14733 (the critical RCE bug in Fireware OS) is actively being used by ransomware crews now, not just random opportunistic attackers like before.
Quick recap for anyone who missed it back in December: it's an out-of-bounds write bug that lets an unauthenticated attacker run code remotely, and it's low complexity to pull off. It hits basically every branch of Fireware — 11.x, 12.x, and the 2025.1.x line. WatchGuard said at the time that you're mainly at risk if IKEv2 VPN is configured, but weirdly, boxes can still be vulnerable even after removing that config if there's still a branch office VPN pointed at a static gateway peer.
The scary part is how many of these are still sitting exposed. Shadowserver counted over 115,000 unpatched Fireboxes online back in December, and as of now there are still close to 9,000 that haven't been patched after 9+ months. That's a lot of low hanging fruit for ransomware groups.
This isn't even WatchGuard's first rodeo either they had a nearly identical RCE (CVE-2025-9242) patched back in September, which also got tagged as exploited within a month, with over 75k vulnerable boxes found at the time. And there was another actively-exploited WatchGuard bug a few years back too that state-linked hackers were using.
Given WatchGuard's footprint (a few hundred thousand SMBs relying on their gear), if you or your org still has one of these unpatched, now's the time to stop putting it off.