logo

New critical WatchGuard Firebox firewall flaw exploited in attacks

ID: bdee4836-53b6-5e5d-af5f-fe14a67cd677

STIX ID: report--bdee4836-53b6-5e5d-af5f-fe14a67cd677

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2025-12-19

Date Updated: 2026-07-17

Author: Sergiu Gatlan

...
...

WatchGuard has warned of a critical, actively exploited unauthenticated remote code execution vulnerability (CVE-2025-14733) impacting Firebox firewalls on Fireware OS 11.x, 12.x and 2025.1 branches. The flaw (out-of-bounds write) can be exploited in low-complexity attacks if devices are configured for IKEv2 VPN; WatchGuard published patches, a temporary workaround for BOVPN configurations, and IoCs, and urged administrators to patch and rotate local secrets. The advisory follows recent similar CVEs (e.g., CVE-2025-9242) and reported large numbers of vulnerable devices and CISA involvement.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.