New! Try the FREE Predictive Security Plugin for WordPress – Scan, Secure & Stay Safe in Seconds!

Current CyberSecurity Advisories

Critical vulnerability in WatchGuard Firebox devices (CVE-2025-14733)

Release date
22 December 2025
Alert rating
Critical

Description

The Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) is aware of active exploitation of a critical vulnerability in WatchGuard Firebox devices.

Audience

Small & medium businessesOrganisations & Critical InfrastructureGovernment

Current update

This alert is relevant to all Australian businesses and organisations.

This alert contains a combination of simple and moderately complex technical advice, intended for business owners and technical IT support services.

Background

ASD’s ACSC is aware of active exploitation of a critical vulnerability in WatchGuard Firebox devices.

An Out-of-Bounds Write vulnerability (CVE-2025-14733) enables an attacker to achieve unauthenticated Remote Code Execution (RCE) in the following vulnerable versions of the Fireware OS:

  • 11.10.2 – 11.12.4_Update1
  • 12.0 – 12.11.5
  • 2025.1 – 2025.1.3

Mitigation advice

Australian organisations should review their networks for vulnerable instances of these devices and upgrade to resolved versions. The WatchGuard Security Advisory includes information about patches and indicators for investigations into suspicious activity.

Where to get help

Organisations that have been impacted, suspect impact or require advice and assistance can contact us via 1300 CYBER1 (1300 292 371).

Protect your assets with Predictive

TisaAssist bot
🤖 Hello, how can I assist you today?
I can help you with:
✅ Answer questions related to the website.
✅ Help you understand things you don't know.
❓ What's Tisalabs
💻 What's IoT
🔒 Why sensor data must be protected?