Threat Actors Exploit Zero-Day in WatchGuard Firebox Devices
These articles are AI-generated summaries. Please check the original sources for full details.
Firebox Devices Under Fire
A zero-day vulnerability in WatchGuard Firebox firewalls, tracked as CVE-2025-14733, is being actively exploited, joining a recent wave of attacks targeting edge devices. CISA added the vulnerability to its KEV catalog on December 23rd, 2025, emphasizing its critical nature.
Ideal network security models assume rapid patching and comprehensive visibility, but in reality, many organizations struggle to apply updates quickly, leaving them exposed to zero-day exploits. The scale of potentially compromised devices – over 125,000 globally – highlights the significant risk and potential cost associated with delayed patching.
Key Insights
- CVE-2025-14733, December 2025: Critical out-of-bounds write in WatchGuard Fireware OS enabling remote code execution.
- Edge Device Targeting: A recent trend demonstrating attackers are focusing on perimeter security appliances (Fortinet, SonicWall, WatchGuard).
- IKED Process Hang: Exploitation of CVE-2025-14733 causes the IKED process to hang, disrupting VPN tunnel negotiations.
Practical Applications
- Use Case: Organizations relying on WatchGuard Firebox for VPN connectivity are at immediate risk and must prioritize patching.
- Pitfall: Delaying patching due to perceived disruption can lead to significant security breaches and data loss.
References:
Continue reading
Next article
Toad: A Unified CLI for LLM Agents with Enhanced UX
Related Content
WatchGuard Fireware OS VPN Vulnerability Under Active Exploitation
WatchGuard addressed CVE-2025-14733, a critical 9.3 CVSS-rated Fireware OS VPN flaw, currently exploited in the wild.
CISA Warns of Actively Exploited Critical Oracle Identity Manager Zero-Day Vulnerability
CISA added CVE-2025-61757, a critical 9.8 CVSS-rated flaw in Oracle Identity Manager, to its KEV catalog due to active exploitation.
WinRAR Vulnerability CVE-2025-6218 Under Active Attack by Multiple Threat Groups
CISA warns WinRAR CVE-2025-6218 is under active attack by multiple threat groups, requiring federal fixes by December 30, 2025.