MCRS Security Advisory
Unpatched Firewalls Have Become a Ransomware Door
CISA has confirmed that ransomware crews are breaking into businesses through an unpatched firewall flaw. If the device protecting your internet line has not been reviewed recently, treat this as urgent.
Jump to Checklist

WHAT BUSINESS OWNERS AND IT LEADS NEED TO KNOW

What has happened

CISA, the United States cyber defense agency, has updated its Known Exploited Vulnerabilities catalogue to confirm that ransomware groups are now exploiting a critical flaw in WatchGuard Firebox firewalls, tracked as CVE-2025-14733.

The flaw sits in the Fireware OS software that runs these firewalls, inside the process that handles IKEv2 VPN connections such as Mobile User VPN and Branch Office VPN. A remote attacker needs no password and only modest skill to run code on an unpatched device.

This is no longer a theoretical warning. Security researchers counted more than 115,000 unpatched, internet-exposed Firebox devices when the flaw was first flagged in December 2025. Nine months later, close to 9,000 are still unsecured.

An attacker sends a specially crafted VPN handshake message to an exposed firewall. On unpatched devices, that message corrupts memory in the VPN service and lets the attacker run code. From there they can take over the firewall completely: intercept traffic, steal VPN credentials and certificates, and use the device as a bridge into the internal network.

Affected releases include Fireware OS 12.x up to 12.11.5 and 2025.1 up to 2025.1.3. Version 11.x is end-of-life and will never receive a fix. Two important details: the flaw is only exploitable where IKEv2 VPN is in use, but simply deleting an old VPN configuration may not be enough if a branch office tunnel to a static gateway peer still exists.

firewalls-enterprise-cve-vulnerability

For a business, a compromised firewall is not a technical inconvenience. It is the perimeter giving way. Attackers who control the firewall can move into the office network, deploy ransomware across servers and staff computers, and hold business data hostage alongside daily operations.

Many small and mid-sized businesses, hotels, schools, clinics, and NGOs run capable but aging edge firewalls that were installed years ago and quietly stopped being managed. That is exactly the profile these campaigns target.

Why this matters

When the firewall falls, everything behind it is exposed. Email, files, accounting systems, client records, CCTV recorders, and payment infrastructure all sit behind that one device.

Ransomware operators have shifted from purely opportunistic email attacks to deliberately hunting unpatched edge devices, because firewalls and VPN appliances are internet-facing by design and often maintained informally. CISA ordered United States federal agencies to fix this specific flaw within one week of listing it. That urgency level is the signal every business should read.

This is also a repeat pattern: an almost identical WatchGuard flaw, CVE-2025-9242, was exploited the same way a year earlier. Unpatched edge equipment is being farmed, not randomly hit.

Who is affected?

  • Businesses running WatchGuard Firebox firewalls on Fireware OS 12.x or 2025.1.x releases.
  • Organizations still using end-of-life Fireware 11.x devices, which have no fix available.
  • Teams using IKEv2 Mobile User VPN or Branch Office VPN tunnels.
  • Businesses whose firewall vendor, subscription, or management arrangement lapsed, leaving the device silently unpatched.
  • Any organization with an aging, internet-facing router, firewall, or VPN appliance of any brand that nobody has reviewed recently.

Warning signs to check

Strange VPN activity
VPN negotiation attempts from unfamiliar external IP addresses in the firewall logs.
VPN service crashes or hangs
Unexpected restarts, crashes, or hangs of the VPN service. A hang is a particularly strong indicator of attack.
Unexplained changes
Configuration changes or VPN sessions appearing that no one on your team made, often following unusual VPN handshake traffic.
No patching record
Nobody can confirm the firmware version, the last update date, or who is responsible for the device.

Immediate action checklist

Step 1: Identify the device and firmware

Confirm what sits on your internet line, who manages it, and which firmware version it runs. If that question takes more than a day to answer, that is a finding in itself.

Step 2: Patch to a fixed release

WatchGuard’s fixed releases are Fireware OS 12.11.6 and 2025.1.4, with 12.5.15 for T15 and T35 models. There is no effective workaround short of patching.

Step 3: Retire end-of-life devices

Fireware 11.x devices will never receive a fix. Remove them from internet exposure and treat them as potentially compromised until they are replaced.

Step 4: Shrink the attack surface

Disable unused Mobile User VPN and Branch Office VPN services, and restrict IKEv2 access where possible. Leftover static branch office tunnels can keep a device exposed even after old VPN configurations are deleted.

Step 5: Rotate secrets after patching

Rotate VPN credentials and certificates after updating. If you suspect the device was accessed, treat it as fully compromised and investigate before trusting it again.

Step 6: Check the logs and set a patch cycle

Review logs for malformed VPN handshake entries, service hangs, and unfamiliar external IPs, using the indicators published in WatchGuard advisory WGSA-2025-00027. Then place firmware updates on a recurring managed cycle so this never silently lapses again.

This is bigger than one vendor

  • Firewalls, routers, VPN appliances, and NAS units are the most exposed equipment a business owns, and attackers now treat unpatched edge devices as the front door for ransomware.
  • Every internet-facing device needs a named owner, a patch cycle, and a replacement plan before it reaches end-of-life.
  • A firewall installed five years ago and never updated is not a security control. It is a liability with a login page.

If nobody in your business can name the device protecting your internet line or its firmware version, start there. MCRS can review your firewall and edge devices, apply updates, harden VPN exposure, and place them on a managed patch cycle. Contact MCRS to schedule an edge-device and firewall review.