Threat Actors Exploit Zero-Day in WatchGuard Firebox Devices
ID: a53c534a-9dc4-5b06-9438-7de0d1b71804
STIX ID: report--a53c534a-9dc4-5b06-9438-7de0d1b71804
Feed Name: Dark Reading
WatchGuard disclosed a critical zero-day (CVE-2025-14733) in Fireware OS affecting Firebox appliances that allows remote code execution via an out-of-bounds write in the IKED process; the vendor reports active exploitation, published an advisory with IoCs and mitigations, and urged immediate patching. CISA added the flaw to its KEV catalog, WatchGuard released a patch on 18 December, and Shadowserver scans found roughly 125,000 potentially vulnerable Firebox IPs worldwide, indicating broad exposure of edge devices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
