Frequent Vulnerabilities in Network Security Devices Keep Corporate Defenses Under Pressure
In January 2025, federal network agencies and researchers again warned that attackers were exploiting a zero-day vulnerability (CVE-2025-0282) in Ivanti Connect Secure. This came about a year after the same product was exploited via two zero-day vulnerabilities (CVE-2023-46805 and CVE-2024-21887). The frequent occurrence of such incidents reveals that security flaws in network defense devices are continuously eroding corporate defenses. Edge devices such as firewalls and VPNs, lacking endpoint detection capabilities, have become preferred initial intrusion points for attackers. Experts point out that despite the risks, these devices will remain in use for the long term, and enterprises need to strengthen vulnerability management while addressing architectural challenges.

As 2025 began, threat hunters and defenders found themselves in the opening scene of a bad sequel. In the first weeks of January, federal cyber authorities and researchers again warned that attackers were exploiting a zero-day vulnerability in Ivanti Connect Secure. The critical unauthenticated stack buffer overflow, tracked as CVE-2025-0282, was discovered and exploited almost exactly one year after the same Ivanti product was hit by a pair of separate zero-days, CVE-2023-46805 and CVE-2024-21887.
The recurrence of new software flaws in the same product from the same vendor might be less nerve-wracking if it weren't so frequent. But this repetition is creating an increasingly unstable environment for enterprises. When the very network devices and services organizations rely on for defense are compromised, they end up fueling the intrusions they were meant to prevent.
Security devices and services running at the edge of enterprise networks—from firewalls and VPNs to routers—have been a common and persistent entry point for cyberattacks. Over the past two years, financially motivated and nation-state-linked attackers have widely exploited vulnerabilities in network edge devices sold by vendors such as Barracuda, Cisco, Citrix, Fortinet, Ivanti, Juniper, Palo Alto Networks, and SonicWall.
Vulnerabilities in cybersecurity tools have impacted organizations across industries, from government agencies to some of the world's most valuable public companies, including Boeing and Comcast. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) was also a victim of the early 2024 wave of Ivanti Connect Secure zero-day exploits, as the agency was using that product for its remote access VPN at the time.
"It's easy to feel fatigued by the endless stream of vulnerabilities, but initial access flaws in these types of network devices are particularly dangerous because the post-exploitation impact is so severe," said Himaja Motheram, security researcher at Censys.
The paradox within cybersecurity gear
Organizations buy and deploy firewalls and VPNs with the intention of strengthening defenses and blocking intrusions. However, the unintended consequences of these purchases and deployments run directly counter to what customers hope to achieve with cybersecurity devices. When malicious hackers exploit vulnerabilities in edge devices, it is not the vendors who suffer the impact, but their customers.
According to research from cyber insurance firm At-Bay, remote access tools such as self-managed VPNs were the primary entry point for ransomware attacks in 2023, accounting for three-fifths of all attacks.
Enterprises that fail to view network edge devices as potential risks are exposing their own networks to danger. Stronger vulnerability management programs can help organizations avoid exploitation, but for zero-days that are already being actively exploited or vulnerabilities that have been publicly disclosed but not yet patched by the vendor, enterprises have little recourse.
"It's easy to overlook a problem if it's not staring you in the face all day," said Kyle Hanslovan, CEO of managed EDR vendor Huntress.
Attackers view cybersecurity devices as prime targets for many reasons. John Dwyer, director of security research at Binary Defense, noted that these devices offer capabilities highly aligned with attacker objectives, including high-privilege access and control. "We don't treat them with the same level of scrutiny as we do other assets on the network, and I think that's a misconception," Dwyer said. "At the end of the day, security tools provide more benefit than harm, but every asset on the network is an attack vector."
According to Dell'Oro Group, firewall sales account for nearly half of total revenue in the cybersecurity market. Palo Alto Networks holds a leading position in the firewall space, with a 29% market share as of the end of the second quarter of 2024, followed by competitors including Fortinet, Cisco, and Check Point Software Technologies. According to CISA's Known Exploited Vulnerabilities catalog, attackers have actively exploited firewall or VPN vulnerabilities from each of these vendors over the past year.
Firewalls and VPNs—the security paradox
Threat groups launching zero-day attacks and exploits against security devices and services are equally aware of an inherent weakness in cybersecurity architecture. Charles Carmakal, CTO of Mandiant Consulting, said at a media briefing during last year's RSA Conference that firewalls, routers, VPNs, and VMware hypervisors "typically do not support endpoint detection and response (EDR) solutions." These systems do not allow administrators to log into the device, view the operating system command line, or browse system files, Carmakal noted, adding that this disadvantage "creates significant challenges for victim organizations to discover that the device has been compromised and malware has been deployed."
EDR products for VPN appliances, routers, and firewalls simply do not exist. "It's very difficult to actually run programs on embedded devices—resources are extremely limited," Hanslovan said. These lightweight devices need to process data with extreme efficiency, and vendors in this space do not allow third-party software to run on their devices or systems.
"You can't install agents on these devices, and you can't tear them apart for incident response," said Raj Samani, senior vice president and chief scientist at Rapid7. "That's exactly why they become targets." Threat groups seeking a foothold in an organization's network "are operating on systems that lack detection capabilities," said Sam Rubin, senior vice president of consulting and threat intelligence at Palo Alto Networks' Unit 42 incident response division. "They're just hiding in a corner of the network, undetected. This happens time and time again," Rubin said.
Edge devices are here to stay
Despite the relentless stream of attacks stemming from software flaws in firewalls, VPNs, and other network edge devices, cybersecurity experts expect them to persist. "I don't see a world where firewalls and VPNs are boycotted into extinction," said Emily Mossburg, global cyber leader at Deloitte. "Firewalls and VPNs are deeply entrenched—they're not going away."
Experts told Cybersecurity Dive that the unresolved problems in enterprise cybersecurity run far deeper than edge devices and their lack of monitoring or endpoint detection. "We're not demanding enough in terms of cultural and architectural change first," Hanslovan said. "In some ways, EDR is addressing a symptom—an important symptom, to be sure—rather than placing more emphasis on root causes." Organizations are rapidly pushing forward with digital transformation and innovation, but they are not paying down old technical debt fast enough, Hanslovan said.
The existing network perimeter architecture and security process frameworks keep defenders in a constant state of anxiety. The creativity and persistence of threat groups allow them to find vulnerabilities in these systems and leverage weaknesses to gain deeper control within victim environments. "The problem with hardware is that updating it is very difficult—if it can even be updated, if it hasn't reached end-of-life, if the manufacturer is still in business," said Sherrod DeGrippo, director of threat intelligence strategy at Microsoft. "We have to find better solutions," DeGrippo said. "I think enterprises unfortunately have to dig deep into the update problem for devices that aren't really hosts and incorporate them into their vulnerability management programs."
