The flaw, tracked as CVE-2025-14733, is an out-of-bounds write vulnerability that allows unauthenticated attackers to execute remote code in low-complexity attacks. It affects Firebox firewalls running Fireware OS 11.x and later (including 11.12.4_Update1), 12.x or later (including 12.11.5), and versions 2025.1 through 2025.1.3.
WatchGuard released security patches in December, at which point it stated that unpatched devices are vulnerable only if configured to use IKEv2 VPN, but warned that devices may still be compromised even if vulnerable configurations have been deleted if a branch office VPN to a static gateway peer remains configured. The company also confirmed that the flaw was being exploited in the wild and shared indicators of compromise.
Internet security watchdog Shadowserver reported over 115,000 unpatched Firebox firewalls exposed online in December. As of September, nearly 9,000 instances remain unsecured.
In a Thursday update to its catalog of actively exploited vulnerabilities, CISA said the flaw is now known to be used by ransomware gangs, though it provided no further details about the attacks. CISA first added the vulnerability to its catalog in December, ordering U.S. federal agencies to secure their systems within a week.