Critical WatchGuard firewall vulnerability exploited in the wild
A critical vulnerability has been found in WatchGuard Fireware OS, used across several of the company's Firebox firewalls. CVE-2025-14733 is rated 9.3 and relates to the VPN component when using IKEv2. It may allow an unauthenticated remote attacker to execute arbitrary code on affected devices, and the vendor states it has already observed attacks abusing the flaw. Patches have been published, along with workarounds where patching is not possible. Affected versions are Fireware OS 11.10.2 through 11.12.4_Update1, 12.0 through 12.11.5, and 2025.1 through 2025.1.3.
What this means for your organisation
The firewall sits at the edge and is reachable from the internet by design. An attacker who gains code execution there is inside, able to read or redirect traffic. Firebox is common among small and mid-sized organisations, often operated by an external provider. Active exploitation makes this urgent.
Berigo recommends
- Confirm today which Fireware version your devices run, and upgrade to a fixed release.
- Where patching cannot happen at once, apply the vendor's recommended workarounds for IKEv2.
- Ask your managed service provider to confirm in writing, with a date, that the update is done.
- Review firewall logs and VPN sign-ins for unexpected activity during December.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch