HomeSecurityCISA: WatchGuard Fireware flaw exposes 54,000 Fireboxes

CISA: WatchGuard Fireware flaw exposes 54,000 Fireboxes

The U.S. Cybersecurity and Infrastructure Security Administration (CISA) on Wednesday added a critical security flaw affecting WatchGuard Fireware to its list of Known Exploitable Vulnerabilities (KEV), based on evidence of active exploitation.

See also: CISA adds Gladinet and CWP vulnerabilities to KEV List

WatchGuard Firewall
CISA: WatchGuard Fireware flaw exposes 54,000 Fireboxes

“WatchGuard Firebox contains an out-of-bounds write vulnerability in the OS iked process that could allow a remote unauthenticated attacker to execute arbitrary code,” CISA said in an advisory.

Details of the vulnerability were disclosed by watchTowr Labs last month, with the cybersecurity firm stating that the problem stems from a lack of length checking in an authentication buffer used during the IKE handshake process.

“The server attempts to verify the certificate, but this verification occurs after the vulnerable code has executed, allowing the vulnerable code path to be accessible before authentication,” security researcher McCaulay Hudson.

See also: CISA: Security Guide for Microsoft Exchange Servers

CISA: WatchGuard Fireware flaw exposes 54,000 Fireboxes
CISA: WatchGuard Fireware flaw exposes 54,000 Fireboxes

At this time, there are no details on how the security flaw is being exploited or the scale of such attempts. According to data from the Shadowserver Foundation,more than 54,300 Firebox instances remain vulnerable to the critical flaw as of November 12, 2025, down from 75,955 on October 19.

About 18,500 of those devices are in the U.S., the scans reveal. Italy (5,400), the United Kingdom (4,000), Germany (3,600) and Canada (3,000) round out the top five. Federal Citizens’ Executive Branch (FCEB) agencies are required to implement WatchGuard updates by December 3, 2025.

See also: CISA warns of vulnerability in VMware Tools and Aria Operations

CISA: WatchGuard Fireware flaw exposes 54,000 Fireboxes
CISA: WatchGuard Fireware flaw exposes 54,000 Fireboxes

This development comes as CISA also added CVE-2025-62215 (CVSS score: 7.0), a recently disclosed vulnerability in the Windows kernel, and CVE-2025-12480 (CVSS score: 9.1), an improper access control vulnerability in Gladinet Triofox, to the KEV list. Google's Mandiant Threat Defense team has attributed the exploitation of CVE-2025-12480 to a threat actor it tracks as UNC6485.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS