Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Why Was The Ferrari 812 GTS Discontinued?

    How To Tell If Your Brake Pads Are Glazed

    ‘The Perfect In-Between Size’ – Why Harbor Freight’s Icon Semi-Deep Sockets Are So Popular

    Facebook X (Twitter) Instagram
    • Artificial Intelligence
    • Business Technology
    • Cryptocurrency
    • Gadgets
    • Gaming
    • Health
    • Software and Apps
    • Technology
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Tech AI Verse
    • Home
    • Artificial Intelligence

      Trump signs executive order seeking to ban states from regulating AI companies

      December 13, 2025

      Apple’s AI chief abruptly steps down

      December 3, 2025

      The issue that’s scrambling both parties: From the Politics Desk

      December 3, 2025

      More of Silicon Valley is building on free Chinese AI

      December 1, 2025

      From Steve Bannon to Elizabeth Warren, backlash erupts over push to block states from regulating AI

      November 23, 2025
    • Business

      Saudia Arabia’s STC commits to five-year network upgrade programme with Ericsson

      December 18, 2025

      Zeroday Cloud hacking event awards $320,0000 for 11 zero days

      December 18, 2025

      Amazon: Ongoing cryptomining campaign uses hacked AWS accounts

      December 18, 2025

      Want to back up your iPhone securely without paying the Apple tax? There’s a hack for that, but it isn’t for everyone… yet

      December 16, 2025

      PlayStation Portal’s Latest Update Proves Sony Needs a Real Handheld Console Again

      December 14, 2025
    • Crypto

      Hyperliquid Denies Insider Trading Allegations as $1 Billion HYPE Burn Vote Approaches

      December 22, 2025

      Nearly 50% of all XRP Supply is Now in Loss as Price Settles Under $2

      December 22, 2025

      Bitcoin’s Underperformance Fuels “Endgame” Fears Amid Gold’s Record Run

      December 22, 2025

      Gate App Unveils Comprehensive Upgrade: Redefining Product Recognition through International Visual Design and Brand Experience

      December 22, 2025

      VET Holders: What to Do After VeChain’s Hayabusa Upgrade

      December 22, 2025
    • Technology

      Why Was The Ferrari 812 GTS Discontinued?

      December 22, 2025

      How To Tell If Your Brake Pads Are Glazed

      December 22, 2025

      ‘The Perfect In-Between Size’ – Why Harbor Freight’s Icon Semi-Deep Sockets Are So Popular

      December 22, 2025

      Are Ego Mowers Repairable? Here’s What You Need To Know

      December 22, 2025

      5 Handy Uses For Your Camera’s USB-C Port

      December 22, 2025
    • Others
      • Gadgets
      • Gaming
      • Health
      • Software and Apps
    Check BMI
    Tech AI Verse
    You are at:Home»Technology»Critical RCE flaw impacts over 115,000 WatchGuard firewalls
    Technology

    Critical RCE flaw impacts over 115,000 WatchGuard firewalls

    TechAiVerseBy TechAiVerseDecember 22, 2025No Comments3 Mins Read0 Views
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    Critical RCE flaw impacts over 115,000 WatchGuard firewalls
    Share
    Facebook Twitter LinkedIn Pinterest WhatsApp Email

    Critical RCE flaw impacts over 115,000 WatchGuard firewalls

    Over 115,000 WatchGuard Firebox devices exposed online remain unpatched against a critical remote code execution (RCE) vulnerability actively exploited in attacks.

    The security flaw, tracked as CVE-2025-14733, affects Firebox firewalls running Fireware OS 11.x and later (including 11.12.4_Update1), 12.x or later (including 12.11.5), and 2025.1 up to and including 2025.1.3.

    Successful exploitation enables unauthenticated attackers to execute arbitrary code remotely on vulnerable devices, following low-complexity attacks that don’t require user interaction.

    As WatchGuard explained in a Thursday advisory, when it released CVE-2025-14733 security updates and tagged it as exploited in the wild, unpatched Firebox firewalls are only vulnerable to attacks if configured for IKEv2 VPN. It also warned that even if vulnerable configurations are removed, the firewall may still be at risk if a Branch Office VPN (BOVPN) to a static gateway peer is still configured.

    “WatchGuard Fireware OS iked process contains an out of bounds write vulnerability in the OS iked process,” an NVD advisory explains. “This vulnerability may allow a remote unauthenticated attacker to execute arbitrary code and affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer.”

    WatchGuard has shared indicators of compromise to help customers identify compromised Firebox appliances on their network, advising those who find signs of malicious activity to rotate all locally stored secrets on vulnerable firewalls. It also provided a temporary workaround for network defenders who can’t immediately patch vulnerable devices, requiring them to disable dynamic peer BOVPNs, add new firewall policies, and disable the default system policies that handle VPN traffic.

    On Saturday, the Internet security watchdog group Shadowserver found over 124,658 unpatched Firebox instances exposed online, with 117,490 still exposed on Sunday.

    WatchGuard firewall instances exposed online (Shadowserver)

    ​One day after WatchGuard released patches, CISA added CVE-2025-14733 to its Known Exploited Vulnerabilities (KEV) Catalog.

    The U.S. cybersecurity agency also ordered Federal Civilian Executive Branch (FCEB) agencies (executive branch non-military agencies, such as the Department of Energy, the Department of the Treasury, and the Department of Homeland Security) to patch Firebox firewalls within a week, by December 26th, as mandated by the Binding Operational Directive (BOD) 22-01.

    “This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise,” CISA warned. “Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.”

    In September, WatchGuard patched an almost identical RCE vulnerability (CVE-2025-9242) impacting Firebox firewalls. One month later, Shadowserver found over 75,000 Firebox firewalls vulnerable to CVE-2025-9242 attacks, most in North America and Europe, with CISA later tagging the security flaw as actively exploited in the wild and ordering federal agencies to secure their Firebox appliances from ongoing attacks.

    Two years ago, CISA also ordered U.S. government agencies to patch another actively exploited WatchGuard flaw (CVE-2022-23176) impacting Firebox and XTM firewall appliances.

    WatchGuard works with over 17,000 security resellers and service providers to protect the networks of more than 250,000 small and mid-sized companies worldwide.


    Break down IAM silos like Bitpanda, KnowBe4, and PathAI

    Broken IAM isn’t just an IT problem – the impact ripples across your whole business.

    This practical guide covers why traditional IAM practices fail to keep up with modern demands, examples of what “good” IAM looks like, and a simple checklist for building a scalable strategy.

    Share. Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Telegram Email
    Previous ArticleDocker Hardened Images now open source and available for free
    Next Article VET Holders: What to Do After VeChain’s Hayabusa Upgrade
    TechAiVerse
    • Website

    Jonathan is a tech enthusiast and the mind behind Tech AI Verse. With a passion for artificial intelligence, consumer tech, and emerging innovations, he deliver clear, insightful content to keep readers informed. From cutting-edge gadgets to AI advancements and cryptocurrency trends, Jonathan breaks down complex topics to make technology accessible to all.

    Related Posts

    Why Was The Ferrari 812 GTS Discontinued?

    December 22, 2025

    How To Tell If Your Brake Pads Are Glazed

    December 22, 2025

    ‘The Perfect In-Between Size’ – Why Harbor Freight’s Icon Semi-Deep Sockets Are So Popular

    December 22, 2025
    Leave A Reply Cancel Reply

    Top Posts

    Ping, You’ve Got Whale: AI detection system alerts ships of whales in their path

    April 22, 2025533 Views

    Lumo vs. Duck AI: Which AI is Better for Your Privacy?

    July 31, 2025189 Views

    6.7 Cummins Lifter Failure: What Years Are Affected (And Possible Fixes)

    April 14, 202593 Views

    6 Best MagSafe Phone Grips (2025), Tested and Reviewed

    April 6, 202579 Views
    Don't Miss
    Technology December 22, 2025

    Why Was The Ferrari 812 GTS Discontinued?

    Why Was The Ferrari 812 GTS Discontinued? The Ferrari 812 GTS has been dead for…

    How To Tell If Your Brake Pads Are Glazed

    ‘The Perfect In-Between Size’ – Why Harbor Freight’s Icon Semi-Deep Sockets Are So Popular

    Are Ego Mowers Repairable? Here’s What You Need To Know

    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    About Us
    About Us

    Welcome to Tech AI Verse, your go-to destination for everything technology! We bring you the latest news, trends, and insights from the ever-evolving world of tech. Our coverage spans across global technology industry updates, artificial intelligence advancements, machine learning ethics, and automation innovations. Stay connected with us as we explore the limitless possibilities of technology!

    Facebook X (Twitter) Pinterest YouTube WhatsApp
    Our Picks

    Why Was The Ferrari 812 GTS Discontinued?

    December 22, 20250 Views

    How To Tell If Your Brake Pads Are Glazed

    December 22, 20250 Views

    ‘The Perfect In-Between Size’ – Why Harbor Freight’s Icon Semi-Deep Sockets Are So Popular

    December 22, 20250 Views
    Most Popular

    What to Know and Where to Find Apple Intelligence Summaries on iPhone

    March 12, 20250 Views

    A Team of Female Founders Is Launching Cloud Security Tech That Could Overhaul AI Protection

    March 12, 20250 Views

    Senua’s Saga: Hellblade 2 leads BAFTA Game Awards 2025 nominations

    March 12, 20250 Views
    © 2025 TechAiVerse. Designed by Divya Tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions

    Type above and press Enter to search. Press Esc to cancel.