Culley said CVE-2025-14733 mirrors CVE-2025-9242’s characteristics closely enough that WatchGuard’s patch cadence looks less like remediation and more like “whack-a-mole” against a class of bug in the same code path.
Culley explained that the mechanism is unauthenticated, low-complexity, and reachable pre-auth wherever IKEv2 VPN or a branch-office tunnel to a static gateway was configured — exactly the always-on, internet-facing service a firewall exists to expose.
“That’s [standard] T1190, external-facing exploitation, straight into whatever lateral movement the ransomware crew brings next,” said Culley. “Patch availability was never the gap. Nine months on, Shadowserver still counts several thousand exposed devices, down from over 115,000 in December — real progress, but not zero, on a device class that sits directly on the network boundary.”
Culley’s advice: patch, then specifically verify IKEv2 and branch-office VPN configurations are the ones the team thinks they are. And, validate that whatever detects post-compromise lateral movement has actually been tested against this device class, not assumed.
Click Here For The Original Source.
