Threat Actors Exploit Zero-Day Vulnerability in WatchGuard Firebox Devices
CriticalExecutive Summary
A zero-day vulnerability, CVE-2025-14733, is under active exploitation in WatchGuard Firebox firewalls, allowing remote code execution. CISA has added this vulnerability to its KEV catalog, urging federal agencies to patch it immediately.
Vulnerability Details
- Affected Product: WatchGuard Firebox Fireware OS versions 11.10.2 up to 11.12.4_Update1, 12.0 or higher, and 2025.1 and higher
- Identifier: CVE-2025-14733
- CVSS Score: 9.3 (Critical)
- Exploitation Status: Actively Exploited
Risk & Impact
- Triage: Immediate patching is critical due to active exploitation and potential for remote code execution.
- Attack Vector: Attackers can send a specially crafted request to the firewall via IKEv2 negotiation, triggering a memory corruption error in the iked process.
- Ease of Exploit: Exploits can be launched remotely over the network, require no authentication, and do not depend on user interaction.
Action Plan
- Immediate Action: Upgrade to Fireware OS versions 2025.1.4, 12.11.6, 12.5.15, or 12.3.1_Update4 (B728352).
- Workaround: Verify strictly if IKEv2 was ever configured. The vulnerability persists in "Zombie" states: if a Mobile/Dynamic VPN was previously configured and deleted, the device remains vulnerable as long as a Static Branch Office VPN exists. Immediate patching is the only reliable fix; merely deleting the dynamic interface is insufficient.
- Detection: Monitor for outbound connections to the listed IOC IP addresses, IKE process hangs or crashes, and abnormally large CERT or IDi payloads in IKE_AUTH requests.
Relevant professional terms
- Zero-Day Vulnerability
- A software vulnerability that is known to the vendor but does not have a patch available, and is actively being exploited by attackers.
- Out-of-Bounds Write
- A type of memory corruption vulnerability that occurs when a program attempts to write data beyond the allocated memory boundaries, potentially leading to arbitrary code execution.
Source: Dark Reading
