WatchGuard Firebox RCE Flaw CVE-2025-14733 Actively Exploited in Ransomware Attacks
CISA has updated its Known Exploited Vulnerabilities catalog to confirm that CVE-2025-14733, a critical unauthenticated remote code execution flaw in WatchGuard Firebox appliances, is being actively used in ransomware attacks. The vulnerability lies in the IKEv2 processing component, allowing attackers to send specially crafted requests from external networks without any authentication. Once exploited, attackers can steal running configurations and local admin user databases, exfiltrating the data to attacker-controlled IP addresses. Indicators of compromise include abnormally large certificate payloads in IKE_AUTH requests, iked process crashes, and unexpected outbound traffic from the appliance. WatchGuard urges immediate patching to the fixed Fireware OS version, and organizations suspecting compromise should rotate all shared secrets, passwords, keys, and certificates.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in