← Vulnerability feed

Vulnerability record · CVE-2025-14733 · published 19 December 2025

CVE-2025-14733: WatchGuard Fireware iked out-of-bounds write allows remote code execution

Watchguard · Fireware

WatchGuard Fireware OS contains an out-of-bounds write in the iked process reachable over the network. It affects IKEv2 mobile user VPN and branch office VPN configurations using a dynamic gateway peer, and Fireboxes may remain exposed even after those configurations are deleted if a static-gateway branch office VPN is still configured. Because it is remotely reachable without authentication, it is a serious edge-device flaw.

9.3 CVSS 4.0 Critical CISA KEV since 19 Dec 2025 Known ransomware use EPSS 27% · top 2.1% CWE-787 · Out-of-bounds write
9.3CVSS 4.0 base score
27%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References
9 Sep 2026Last modified by NVD

Description

An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer. If the Firebox was previously configured with the mobile user VPN with IKEv2 or a branch office VPN using IKEv2 to a dynamic gateway peer, and both of those configurations have since been deleted, that Firebox may still be vulnerable if a branch office VPN to a static gateway peer is still configured.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityRemote unauthenticated code execution on an internet-facing VPN gateway that is in CISA KEV with known ransomware use and a near-term remediation deadline.

What it is

WatchGuard Fireware OS contains an out-of-bounds write in the iked process reachable over the network. It affects IKEv2 mobile user VPN and branch office VPN configurations using a dynamic gateway peer, and Fireboxes may remain exposed even after those configurations are deleted if a static-gateway branch office VPN is still configured. Because it is remotely reachable without authentication, it is a serious edge-device flaw.

Impact

A remote unauthenticated attacker can execute arbitrary code on the Firebox, giving full control of the VPN gateway and a foothold at the network perimeter.

Attack surface

Reached over the network through the IKEv2 service on the Firebox; the CVSS vector shows no privileges or user interaction required. Any Firebox running an affected Fireware OS with the described IKEv2 configurations is exposed.

Exploitation

CISA added this to the Known Exploited Vulnerabilities catalog on 2025-12-19 with a 2025-12-26 remediation due date and flags known ransomware campaign use, indicating active exploitation. EPSS gives a 30-day exploitation probability of about 26.5 percent (97.9th percentile).

What to do

  • Apply the WatchGuard Fireware OS update referenced in advisory WGSA-2025-00027 as soon as possible.
  • If patching is not immediately possible, disable IKEv2 mobile user VPN and IKEv2 branch office VPN configurations, including any static-gateway branch office VPN on devices that previously used the affected configurations.
  • Restrict IKEv2 access to known peer addresses where operationally feasible.
  • Follow CISA BOD 22-01 guidance and treat the 2025-12-26 due date as the remediation deadline.
  • Review Firebox configurations for the affected IKEv2 setups and confirm removal or patching on every device.

Detection

  • Monitor Firebox and perimeter logs for unexpected iked process crashes or restarts.
  • Alert on anomalous IKEv2 traffic to the Firebox from untrusted or unexpected source addresses.
  • Hunt for signs of post-exploitation activity on the Firebox, such as unexpected configuration changes, new accounts or outbound connections.
  • Correlate Firebox logs with downstream network telemetry for lateral movement or ransomware staging from the VPN gateway.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-14733 to the Known Exploited Vulnerabilities catalog on 19 December 2025 as "WatchGuard Firebox Out of Bounds Write Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 26 December 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-14733 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-26318WatchGuard Fireware OS unauthenticated remote code executionWatchGuard Firebox and XTM appliances running Fireware OS contain an unauthenticated remote code execution flaw tracked as FBX-22786. An attacker who…KEVEPSS 78%analysed9.3CVE-2025-9242WatchGuard Fireware OS iked out-of-bounds writeWatchGuard Fireware OS contains an out-of-bounds write in the iked process that can let a remote, unauthenticated attacker execute arbitrary code. It…KEVEPSS 91%analysed8.8CVE-2022-23176WatchGuard Fireware management access privilege escalationWatchGuard Firebox and XTM appliances running Fireware OS allow a remote attacker holding unprivileged credentials to obtain a privileged management …KEVEPSS 11%analysed9.8CVE-2022-31789Watchguard fireware integer overflow vulnerabilityAn integer overflow in WatchGuard Firebox and XTM appliances allows an unauthenticated remote attacker to trigger a buffer overflow and potentially e…EPSS 1.9%9.3CVE-2013-6021Watchguard fireware memory buffer overflow vulnerabilityBuffer overflow in WGagent in WatchGuard WSM and Fireware before 11.8 allows remote attackers to execute arbitrary code via a long sessionid value in…EPSS 12%9.2CVE-2026-13368Watchguard fireware use after free vulnerabilityWatchGuard Fireware OS contains a race condition leading to a use-after-free vulnerability in LDAP authentication for the Mobile User VPN with IKEv2.…EPSS 0.94%9.1CVE-2022-25361Watchguard fireware vulnerabilityWatchGuard Firebox and XTM appliances allow an unauthenticated remote attacker to delete arbitrary files from a limited set of directories on the sys…EPSS 1.3%8.8CVE-2022-25291Watchguard fireware integer overflow vulnerabilityAn integer overflow in WatchGuard Firebox and XTM appliances allows an authenticated remote attacker to trigger a heap-based buffer overflow and pote…EPSS 1.8%

Source: NIST National Vulnerability Database (record CVE-2025-14733), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.