{"id":9338,"date":"2025-12-19T10:00:33","date_gmt":"2025-12-19T10:00:33","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/12\/19\/watchguard-0-day-vulnerability-exploited-in-the-wild-to-hijack-firewalls\/"},"modified":"2025-12-19T10:00:33","modified_gmt":"2025-12-19T10:00:33","slug":"watchguard-0-day-vulnerability-exploited-in-the-wild-to-hijack-firewalls","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/12\/19\/watchguard-0-day-vulnerability-exploited-in-the-wild-to-hijack-firewalls\/","title":{"rendered":"WatchGuard 0-day Vulnerability Exploited in the Wild to Hijack Firewalls"},"content":{"rendered":"<p>    WatchGuard 0-day Vulnerability Exploited in the Wild to Hijack Firewalls<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>An urgent security update has been released to fix a critical zero-day vulnerability in <a href=\"https:\/\/cybersecuritynews.com\/watchguard-firebox-firewall-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">WatchGuard Firebox<\/a> firewalls. With warnings that hackers are already actively exploiting the flaw in the wild to take control of affected devices.<\/p>\n<p>The vulnerability, tracked as\u00a0CVE-2025-14733, carries a critical severity score of\u00a09.3 out of 10. It allows a remote attacker to execute malicious code on the <a href=\"https:\/\/cybersecuritynews.com\/open-source-firewall-ipfire\/\" target=\"_blank\" rel=\"noreferrer noopener\">firewall <\/a>without needing a username or password.<\/p>\n<p>The issue is described as an \u201c<a href=\"https:\/\/cybersecuritynews.com\/out-of-bounds-read-and-write\/\" target=\"_blank\" rel=\"noreferrer noopener\">Out-of-bounds Write<\/a>\u201d vulnerability located in the\u00a0ike process, which handles VPN connections on the device.<\/p>\n<p>Specifically, the flaw affects the Mobile User VPN and Branch Office VPN (when using IKEv2). It occurs when the system tries to process a connection request.<\/p>\n<p>If an attacker sends a specially crafted request, they can corrupt the system\u2019s memory and hijack the firewall.<\/p>\n<p>WatchGuard noted that even <span style=\"box-sizing: border-box; margin: 0px; padding: 0px;\">after deleting a\u00a0<a href=\"https:\/\/cybersecuritynews.com\/watchguard-vpn-vulnerability\/\" target=\"_blank\" rel=\"noopener\">vulnerable VPN<\/a>\u00a0configuration, your device may remain at risk if a Branch Office VPN with a static gateway remains<\/span> active.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-active-0-day-exploitation-detected\"><strong>Active 0-Day Exploitation Detected<\/strong><\/h2>\n<p>WatchGuard confirmed they have \u201cobserved threat actors actively attempting to exploit this vulnerability.\u201d To help administrators defend their networks, they released specific indicators of compromise (<a href=\"https:\/\/cybersecuritynews.com\/acr-stealer-uncovering-attack-chains\/\" target=\"_blank\" rel=\"noreferrer noopener\">IoCs<\/a>).<\/p>\n<p>Suspicious IP Addresses:<\/p>\n<figure class=\"wp-block-table is-style-stripes\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th>Suspicious IP Address<\/th>\n<th>Indicator<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>45.95.19[.]50<\/td>\n<td>Strong sign of attack-related traffic<\/td>\n<\/tr>\n<tr>\n<td>51.15.17[.]89<\/td>\n<td>Strong sign of attack-related traffic<\/td>\n<\/tr>\n<tr>\n<td>172.93.107[.]67<\/td>\n<td>Strong sign of attack-related traffic<\/td>\n<\/tr>\n<tr>\n<td>199.247.7[.]82<\/td>\n<td>Strong sign of attack-related traffic<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>Administrators should check their logs for:<\/p>\n<figure class=\"wp-block-table is-style-stripes\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th>Indicator<\/th>\n<th>Description<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><strong>Large Certificate Payloads<\/strong><\/td>\n<td>Logs show an IKE_AUTH request with a CERT size greater than 2000 bytes<\/td>\n<\/tr>\n<tr>\n<td><strong>Long Certificate Chains<\/strong><\/td>\n<td>Errors report: \u201cReceived peer certificate chain is longer than 8\u201d<\/td>\n<\/tr>\n<tr>\n<td><strong>Process Crashes<\/strong><\/td>\n<td>The iked process suddenly hangs or crashes, which may signal an exploit attempt<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>WatchGuard has <a href=\"https:\/\/www.watchguard.com\/wgrd-psirt\/advisory\/wgsa-2025-00027\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">released<\/a> software updates to fix the issue. Admins should upgrade to the following versions immediately:<\/p>\n<figure class=\"wp-block-table is-style-stripes\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th>Current Fireware OS Version<\/th>\n<th>Recommended Upgrade Version<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><strong>Fireware OS 2025.1<\/strong><\/td>\n<td>Upgrade to <strong>2025.1.4<\/strong>\n<\/td>\n<\/tr>\n<tr>\n<td><strong>Fireware OS 12.x<\/strong><\/td>\n<td>Upgrade to <strong>12.11.6<\/strong>\n<\/td>\n<\/tr>\n<tr>\n<td><strong>Fireware OS 12.5.x (T15\/T35)<\/strong><\/td>\n<td>Upgrade to <strong>12.5.15<\/strong>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>If you find evidence that your device was targeted, simply installing <a href=\"https:\/\/cybersecuritynews.com\/sap-security-patch-day-december\/\" target=\"_blank\" rel=\"noreferrer noopener\">the patch<\/a> is not enough. WatchGuard recommends rotating all shared secrets (passwords and keys) stored on the device, as attackers may have stolen them.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 92%,rgb(169,184,195) 100%)\"><strong>AI-Powered ISO 27001, SOC 2, NIST, NIS 2, and GDPR Compliance Checklist =&gt; <a href=\"https:\/\/www.aiauditbuddy.com\/?utm_source=newsletter&amp;utm_medium=email&amp;utm_campaign=cybersecuritynews_feature\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Start for Free<\/a><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/watchguard-0-day-vulnerability-exploited\/\">WatchGuard 0-day Vulnerability Exploited in the Wild to Hijack Firewalls<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/watchguard-0-day-vulnerability-exploited\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>WatchGuard 0-day Vulnerability Exploited in the Wild to Hijack Firewalls An urgent security update has been released to fix a critical zero-day vulnerability in WatchGuard Firebox firewalls. With warnings that hackers are already actively exploiting the flaw in the wild to take control of affected devices. The vulnerability, tracked as\u00a0CVE-2025-14733, carries a critical severity score [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,131,648,517],"tags":[130],"class_list":["post-9338","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability","category-vulnerability-news","category-zero-day","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9338"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=9338"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9338\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=9338"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=9338"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=9338"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}