Cyber Security News

WatchGuard 0-day Vulnerability Exploited in the Wild to Hijack Firewalls

An urgent security update has been released to fix a critical zero-day vulnerability in WatchGuard Firebox firewalls. With warnings that hackers are already actively exploiting the flaw in the wild to take control of affected devices.

The vulnerability, tracked as CVE-2025-14733, carries a critical severity score of 9.3 out of 10. It allows a remote attacker to execute malicious code on the firewall without needing a username or password.

The issue is described as an “Out-of-bounds Write” vulnerability located in the ike process, which handles VPN connections on the device.

Specifically, the flaw affects the Mobile User VPN and Branch Office VPN (when using IKEv2). It occurs when the system tries to process a connection request.

If an attacker sends a specially crafted request, they can corrupt the system’s memory and hijack the firewall.

WatchGuard noted that even after deleting a vulnerable VPN configuration, your device may remain at risk if a Branch Office VPN with a static gateway remains active.

Active 0-Day Exploitation Detected

WatchGuard confirmed they have “observed threat actors actively attempting to exploit this vulnerability.” To help administrators defend their networks, they released specific indicators of compromise (IoCs).

Suspicious IP Addresses:

Suspicious IP AddressIndicator
45.95.19[.]50Strong sign of attack-related traffic
51.15.17[.]89Strong sign of attack-related traffic
172.93.107[.]67Strong sign of attack-related traffic
199.247.7[.]82Strong sign of attack-related traffic

Administrators should check their logs for:

IndicatorDescription
Large Certificate PayloadsLogs show an IKE_AUTH request with a CERT size greater than 2000 bytes
Long Certificate ChainsErrors report: “Received peer certificate chain is longer than 8”
Process CrashesThe iked process suddenly hangs or crashes, which may signal an exploit attempt

WatchGuard has released software updates to fix the issue. Admins should upgrade to the following versions immediately:

Current Fireware OS VersionRecommended Upgrade Version
Fireware OS 2025.1Upgrade to 2025.1.4
Fireware OS 12.xUpgrade to 12.11.6
Fireware OS 12.5.x (T15/T35)Upgrade to 12.5.15

If you find evidence that your device was targeted, simply installing the patch is not enough. WatchGuard recommends rotating all shared secrets (passwords and keys) stored on the device, as attackers may have stolen them.

AI-Powered ISO 27001, SOC 2, NIST, NIS 2, and GDPR Compliance Checklist => Start for Free

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

2 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

3 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

4 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

4 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

4 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

6 hours ago