Vulnerability record · CVE-2025-14733 · published 19 December 2025
CVE-2025-14733: WatchGuard Fireware iked out-of-bounds write allows remote code execution
Watchguard · Fireware
WatchGuard Fireware OS contains an out-of-bounds write in the iked process reachable over the network. It affects IKEv2 mobile user VPN and branch office VPN configurations using a dynamic gateway peer, and Fireboxes may remain exposed even after those configurations are deleted if a static-gateway branch office VPN is still configured. Because it is remotely reachable without authentication, it is a serious edge-device flaw.
Description
An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer. If the Firebox was previously configured with the mobile user VPN with IKEv2 or a branch office VPN using IKEv2 to a dynamic gateway peer, and both of those configurations have since been deleted, that Firebox may still be vulnerable if a branch office VPN to a static gateway peer is still configured.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Automated analysis
critical priorityRemote unauthenticated code execution on an internet-facing VPN gateway that is in CISA KEV with known ransomware use and a near-term remediation deadline.
What it is
WatchGuard Fireware OS contains an out-of-bounds write in the iked process reachable over the network. It affects IKEv2 mobile user VPN and branch office VPN configurations using a dynamic gateway peer, and Fireboxes may remain exposed even after those configurations are deleted if a static-gateway branch office VPN is still configured. Because it is remotely reachable without authentication, it is a serious edge-device flaw.
Impact
A remote unauthenticated attacker can execute arbitrary code on the Firebox, giving full control of the VPN gateway and a foothold at the network perimeter.
Attack surface
Reached over the network through the IKEv2 service on the Firebox; the CVSS vector shows no privileges or user interaction required. Any Firebox running an affected Fireware OS with the described IKEv2 configurations is exposed.
Exploitation
CISA added this to the Known Exploited Vulnerabilities catalog on 2025-12-19 with a 2025-12-26 remediation due date and flags known ransomware campaign use, indicating active exploitation. EPSS gives a 30-day exploitation probability of about 26.5 percent (97.9th percentile).
What to do
- Apply the WatchGuard Fireware OS update referenced in advisory WGSA-2025-00027 as soon as possible.
- If patching is not immediately possible, disable IKEv2 mobile user VPN and IKEv2 branch office VPN configurations, including any static-gateway branch office VPN on devices that previously used the affected configurations.
- Restrict IKEv2 access to known peer addresses where operationally feasible.
- Follow CISA BOD 22-01 guidance and treat the 2025-12-26 due date as the remediation deadline.
- Review Firebox configurations for the affected IKEv2 setups and confirm removal or patching on every device.
Detection
- Monitor Firebox and perimeter logs for unexpected iked process crashes or restarts.
- Alert on anomalous IKEv2 traffic to the Firebox from untrusted or unexpected source addresses.
- Hunt for signs of post-exploitation activity on the Firebox, such as unexpected configuration changes, new accounts or outbound connections.
- Correlate Firebox logs with downstream network telemetry for lateral movement or ransomware staging from the VPN gateway.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-14733 to the Known Exploited Vulnerabilities catalog on 19 December 2025 as "WatchGuard Firebox Out of Bounds Write Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 26 December 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://psirt.watchguard.com/CVE-2025-14733 | Broken Link |
| https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2025-00027 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-14733 | US Government Resource |
Track CVE-2025-14733 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-14733), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.