Over 115,000 WatchGuard Firebox devices exposed online remain unpatched against a critical RCE vulnerability being actively exploited. Security experts warn of the risks posed by this flaw, especially for Firebox firewalls configured with IKEv2 VPN. #CVE-2025-14733 #WatchGuardFirebox
Keypoints
- Over 115,000 WatchGuard Firebox devices are exposed to a critical remote code execution vulnerability.
- The vulnerability, CVE-2025-14733, affects Fireware OS versions 11.x, 12.x, and 2025.1, and is actively exploited in attacks.
- Exploitation allows attackers to execute remote code without authentication, especially on VPN-configured devices.
- WatchGuard issued security updates but many devices remain unpatched, increasing their susceptibility.
- Federal agencies are mandated to patch these vulnerabilities within a specified timeframe to prevent widespread attacks.