Ransomware Gangs Exploiting Critical WatchGuard Firebox Vulnerability
The U.S. Cybersecurity and Infrastructure Security Agency (**CISA**) has confirmed that ransomware groups are now actively exploiting a critical out-of-bounds write vulnerability in **WatchGuard Firebox** firewalls. Tracked as **CVE-2025-14733**, this flaw allows unauthenticated attackers to execute remote code, posing a significant threat to organizations relying on these devices for network security.

The **U.S. Cybersecurity and Infrastructure Security Agency (CISA)** has issued a stark warning: ransomware gangs are actively exploiting a critical vulnerability in **WatchGuard Firebox** firewalls. This flaw, **CVE-2025-14733**, was first flagged by **CISA** as actively exploited in December and has since become a tool in the arsenal of sophisticated threat actors.
### The Nature of the Flaw
**CVE-2025-14733** is an out-of-bounds write vulnerability that allows unauthenticated attackers to execute malicious code remotely. The attacks are described as having low complexity, making them particularly dangerous.
### Affected Devices and Patching
The vulnerability impacts **Fireware OS** versions 11.x and later (including 11.12.4_Update1), 12.x or later (including 12.11.5), and 2025.1 through 2025.1.3.
**WatchGuard** released security patches for **CVE-2025-14733** in December. The company initially stated that unpatched **Firebox** firewalls are vulnerable only if configured to use **IKEv2 VPN**. However, they also warned that devices might still be compromised even if vulnerable configurations are deleted, provided a branch office VPN to a static gateway peer remains active.
### Widespread Exposure
Upon the initial disclosure, internet security watchdog group **Shadowserver** identified over 115,000 unpatched **Firebox** firewalls exposed online. Disturbingly, nine months later, nearly 9,000 instances remain unsecured, leaving countless organizations vulnerable.

*Vulnerable WatchGuard firewalls exposed online (**Shadowserver**)*
### CISA's Ongoing Warnings
In a recent update to its Known Exploited Vulnerabilities (**KEV**) catalog, **CISA** specifically noted the involvement of ransomware gangs in exploiting **CVE-2025-14733**. While further details on these specific attacks have not been released, the confirmation underscores the severity and immediate threat.
**CISA** added this flaw to its **KEV** catalog in December, mandating that U.S. federal agencies patch their systems within a week, as per Binding Operational Directive (**BOD**) 22-01.
This isn't the first time **WatchGuard** devices have been targeted. Two years prior, **CISA** ordered government agencies to patch another actively exploited **WatchGuard** flaw (**CVE-2022-23176**) affecting **Firebox** and **XTM** firewalls. More recently, in September 2025, **WatchGuard** patched **CVE-2025-9242**, another critical RCE vulnerability in **Firebox** firewalls, which **CISA** also later tagged as actively exploited.
**WatchGuard** serves over 250,000 small and mid-sized companies globally through a network of more than 17,000 security resellers and service providers. The widespread deployment of these devices means the potential impact of such vulnerabilities is immense.