logo

125,000 IPs WatchGuard Firebox Devices Exposed to Internet Vulnerable to 0-day RCE Attacks

ID: 865a7de3-eae7-5672-8c3e-5c752bc64989

STIX ID: report--865a7de3-eae7-5672-8c3e-5c752bc64989

Feed Name: cybersecurityNews.com

Threat Score
92/100

Date Published: 2025-12-22

Date Updated: 2026-04-21

Author: Abinaya

...
...

A critical unauthenticated RCE zero-day (CVE-2025-14733, CVSS 9.8) in WatchGuard Fireware OS's iked IKEv2 implementation is being actively exploited in the wild, exposing roughly 125,000 Firebox devices; Shadowserver and WatchGuard published affected versions, mitigation updates, and IOCs—organizations are urged to patch immediately, monitor VPN/IKE logs for anomalous IKE_AUTH payloads, and rotate credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.