Back to all lessons
Awareness Lessons
last month

Unpatched WatchGuard Firewalls Exploited in Ransomware Campaigns

A critical unauthenticated RCE vulnerability (CVE-2025-14733) in WatchGuard Firebox firewalls is being actively exploited by ransomware gangs, despite patches being available since December. The flaw requires no credentials and low attack complexity, making it trivially easy for threat actors to compromise internet-facing devices. This incident highlights a dangerous gap between patch availability and patch deployment, particularly for perimeter security appliances that protect the entire network. When firewall devices themselves become the entry point, the consequences can be catastrophic — ransomware can propagate freely once attackers establish an initial foothold behind the perimeter.

Tactical Insight

Immediate actions

  • Apply WatchGuard's December patch to all Firebox devices without delay, prioritizing those configured for IKEv2 VPN.
  • Review WatchGuard's published IOCs immediately to determine if any devices have already been compromised.
  • Temporarily disable IKEv2 VPN functionality on unpatched devices until the patch can be applied.

Long-term improvements

  • Establish a maximum patch window SLA (e.g., 48–72 hours) for critical vulnerabilities on internet-facing and perimeter devices.
  • Maintain a continuously updated inventory of all network appliances, firmware versions, and exposed services.
  • Implement network segmentation so that a compromised perimeter device cannot provide direct access to critical internal systems.

Detection measures

  • Deploy automated vulnerability scanning specifically targeting internet-facing assets on a daily or continuous basis.
  • Configure SIEM alerting for anomalous outbound traffic or unexpected administrative activity originating from firewall devices.
  • Subscribe to vendor security advisories and CISA KEV (Known Exploited Vulnerabilities) catalog updates to ensure timely awareness of actively exploited flaws.