CISA has confirmed that ransomware gangs are exploiting CVE-2025-14733, a critical WatchGuard Firebox firewall flaw that allows unauthenticated remote code execution through an out-of-bounds write. WatchGuard and Shadowserver reported widespread exposure of unpatched Firebox devices, with tens of thousands still vulnerable online. #CVE202514733 #WatchGuardFirebox #Shadowserver #CISA
Keypoints
- CVE-2025-14733 is a critical WatchGuard Firebox vulnerability.
- The flaw can let unauthenticated attackers execute code remotely.
- Fireware OS 11.x, 12.x, and 2025.1 branches are affected.
- WatchGuard warned systems may remain at risk even after some settings are removed.
- CISA says ransomware gangs are now using the flaw in attacks.