WatchGuard Firebox Flaw CVE-2025-14733 Now Used by Ransomwar
Information Technology Solutions for Dentists and the Dental Industry. Serving the GTA and Southern Ontario.
Dental I/T, Dental Information Technology, Network Security, Toronto, GTA, Dental, Network, I/T, Information Technology, Computer, Data, Abeldent, Dentrix, LiveDDM, Patterson Dental, Henry Schein, K-Dental, Sinclair Dental, Schick CDR, Dexis, Carestream, Carestream Dental, Digital Radiography, X-ray, Dental X-ray, Dental Software Support, Software
18685
bp-nouveau,wp-singular,post-template-default,single,single-post,postid-18685,single-format-standard,wp-theme-bridge,wp-child-theme-bridge-child,theme-bridge,woocommerce-no-js,ajax_fade,page_not_loaded,,columns-4,qode-child-theme-ver-1.0.0,qode-theme-ver-10.0,wpb-js-composer js-comp-ver-4.12,vc_responsive

Ransomware Is Now Using It: The WatchGuard Firewall Flaw Your Practice Can’t Leave Unpatched

A firewall drawn as a cracked gateway at the edge of a practice network, with malicious traffic slipping past the broken lock toward interior systems

Ransomware Is Now Using It: The WatchGuard Firewall Flaw Your Practice Can’t Leave Unpatched

On September 10, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) updated its catalog of actively exploited vulnerabilities to confirm something practices should not ignore: ransomware gangs are now exploiting a critical flaw in WatchGuard Firebox firewalls (BleepingComputer, CISA: WatchGuard RCE flaw now exploited in ransomware attacks). The bug, CVE-2025-14733, has been public and patched since December 2025 – but nine months on, thousands of these firewalls are still hanging open on the internet, and the criminals who deploy ransomware have now added them to their target list. If your dental office runs a WatchGuard firewall, this is a today problem, not a someday problem.

What makes this flaw different from the usual alert

Most of the security warnings a practice sees describe attacks that need several steps: a staff member has to open a phishing email, a password has to be stolen, a foothold has to be established before an attacker can move. This one skips all of that. CVE-2025-14733 is an unauthenticated remote-code-execution flaw – technically an out-of-bounds write in the firewall’s software – and it can be exploited in low-complexity attacks. In plain terms: an attacker who can reach your firewall over the internet can run their own code on it without any login, password or click from your staff. There is no foothold to establish because the firewall itself is the foothold. And the firewall is not some minor gadget – it is the internet-facing front door to your entire practice network, the device that stands between the open internet and your practice-management server, your imaging PCs and every record of patient health information you hold.

Which devices are affected

The flaw affects WatchGuard Firebox appliances running Fireware OS 11.x and later (including 11.12.4_Update1), 12.x and later (including 12.11.5), and the 2025.1 through 2025.1.3 releases. According to WatchGuard’s own advisory, a Firebox is exposed when it is configured to use the IKEv2 VPN – the feature many practices turn on so a dentist or a remote hygienist can connect securely from home. Here is the part that trips people up: WatchGuard warns that a device may still be vulnerable even if you deleted the vulnerable VPN configuration, as long as a branch-office VPN to a static gateway peer is still configured. “We turned that off ages ago” is not the same as “we are safe.” The only way to know is to check the firmware version and the current configuration directly.

Nine months, and thousands are still open

This is the uncomfortable pattern with edge devices. The internet-monitoring group Shadowserver counted roughly 115,000 exposed Fireboxes when the flaw went public in December; nine months later, nearly 9,000 remain unpatched and reachable online. Firewalls, routers and VPN appliances are the perfect ransomware target precisely because they are the devices everyone installs and then forgets – they sit in a closet, they “just work,” nobody logs in for a year, and their firmware quietly rots. This is not a WatchGuard-only failing; it is the same reason we recently had to sound the alarm about actively exploited flaws in practice routers. Attackers know these boxes are neglected, and CISA has now confirmed they are walking straight through this one. For context, this is not even the first WatchGuard flaw to draw this level of attention – an earlier Firebox vulnerability was exploited by Russian state-linked hackers two years ago. Edge devices are a permanent front line, not a one-time chore.

Why a firewall breach becomes a ransomware disaster

When an attacker compromises the firewall, they are not stuck at the edge – they are inside the perimeter, on the one device that can see and route to everything else. From there the ransomware playbook is well worn: map the internal network, reach the practice server, disable backups, encrypt patient records and imaging data, and leave a ransom note. We have watched exactly this kind of chain end badly for dental organizations when it starts with a trusted third party – the recent billing-vendor ransomware attack that put practices on a leak site is a reminder of how fast “one compromised system” becomes “our patients’ data is for sale.” A pre-authentication flaw on your own firewall removes even the need for a third party. And the fallout is not only technical: under PHIPA, a ransomware event that exposes patient information is a reportable privacy breach, with all the notification, regulatory and reputational weight that carries.

What your practice should do this week

The fix is genuinely fast – the hard part is simply doing it. 1. Find out what you have. Confirm whether your practice runs a WatchGuard Firebox and, if so, which Fireware version. If you don’t know, that uncertainty is itself the finding. 2. Upgrade the firmware now. WatchGuard released fixed Fireware versions in December; updating to a patched release closes the hole. This is a scheduled, out-of-hours job on the firewall, not a workstation reboot. 3. Retire VPN configs you don’t use. Disable IKEv2 and old branch-office VPN configurations you no longer need – but verify against WatchGuard’s advisory, because a leftover static-peer config can keep you exposed. 4. Check for signs you were already hit. WatchGuard published indicators of compromise so customers can tell whether a device was attacked before it was patched; if you were exposed for months, assume-breach and look. 5. Don’t stop at the firewall. Patch Tuesday covers Windows, but your firewall, router and phone system run on their own calendars – a complete posture patches all of them, and the machines that genuinely cannot be patched get segmented off so a perimeter breach can’t reach them. If you missed this month’s Windows update, our breakdown of September’s record Patch Tuesday shows how to prioritize.

What this means for your practice

A firewall is supposed to be the thing that protects the practice – which is exactly why a flaw in it is so serious, and why “we have a firewall” is not the same as “our firewall is current.” An unpatched edge device is worse than no firewall, because it gives you the confidence of protection while quietly serving as the attacker’s way in. The practices that stay safe are not the ones that never buy a WatchGuard; they are the ones whose firewalls, routers and VPN appliances are inventoried, monitored and patched on a schedule instead of installed and forgotten. Compudent manages edge security for dental practices across Ontario – tracking firmware across your firewall and network gear, applying critical patches like this one on a tight schedule, hardening remote-access VPNs, and checking exposed devices against advisories the moment they land. If you are not certain whether your practice firewall is patched against CVE-2025-14733 – or you’re not sure what firewall you even have – contact Compudent for an edge-security assessment. We will find out where you stand and close anything that’s still open.


Sources & further reading:

Related Reading



Contact us today - How can we help you?