Ransomware Gangs Exploit Critical WatchGuard Firebox RCE (CVE‑2025‑14733)
What Happened — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed that ransomware groups are actively exploiting a critical remote‑code‑execution flaw in WatchGuard Firebox firewalls (CVE‑2025‑14733). The vulnerability allows unauthenticated attackers to execute code remotely via an out‑of‑bounds write, and it has been observed in the wild against unpatched devices.
Why It Matters for Trust & Control Assurance
- Demonstrates the risk of unpatched third‑party network security appliances – a control gap that a continuous vendor‑risk program is designed to surface and remediate.
- Highlights the need for real‑time evidence that patching policies are enforced across all firewall assets, supporting a defensible audit trail.
- Shows how a single unaddressed vulnerability can become a ransomware entry point, underscoring the importance of automated vulnerability‑management controls.
Who Is Affected – Small‑ and mid‑size enterprises that rely on WatchGuard Firebox firewalls, as well as any organization whose network perimeter includes unpatched Fireware OS 11.x/12.x devices.
Recommended Actions
- Verify the firmware version on every WatchGuard device; apply the December 2025 security patch immediately.
- Enable continuous monitoring of third‑party asset inventories to flag out‑of‑date firewalls.
- Document patch‑deployment evidence in a central Trust Center to satisfy audit requirements. Source: BleepingComputer
Technical Notes – CVE‑2025‑14733 is an out‑of‑bounds write that can be triggered via IKEv2 VPN traffic, allowing unauthenticated remote code execution. The flaw affects Fireware OS 11.x (including 11.12.4_Update1), 12.x (including 12.11.5), and versions 2025.1‑2025.1.3. Source: CISA KEV Catalog