CVE-2025-14733
9.5 CISA KEVWatchGuard · Firebox
An out of bounds write vulnerability in the WatchGuard Fireware OS iked process allows remote unauthenticated attackers to execute arbitrary code.
Executive summary
A critical out of bounds write vulnerability in WatchGuard Firebox appliances is currently being exploited in the wild, posing a severe risk of remote code execution.
Vulnerability
This is an out of bounds write flaw (CWE-787) in the iked process of the Fireware OS. It allows an unauthenticated remote attacker to execute arbitrary code via specially crafted IKEv2 packets, affecting both mobile user VPN and branch office VPN configurations.
Business impact
The CVSS score of 9.5 classifies this as a critical vulnerability, reflecting the high potential for full system compromise. Successful exploitation grants an attacker the ability to execute arbitrary code, which could lead to unauthorized network access, data exfiltration, or complete loss of control over the security appliance. Given that this is an edge device, the risk to the entire internal network is extreme.
Remediation
Immediate Action: Update all affected Firebox appliances to Fireware OS 2025.1.4, 12.11.6, 12.5.15, or 12.3.1-b728352 immediately. Additionally, if threat actor activity is confirmed on the appliance, you must rotate all locally stored secrets as outlined in the vendor best practices documentation.
Proactive Monitoring: Monitor logs for anomalous IKEv2 traffic or unexpected crashes of the iked process. Ensure that VPN configurations are audited to identify if vulnerable setups, such as dynamic gateway peers, are in use.
Compensating Controls: While a patch is the only definitive fix, ensure that perimeter security policies restrict IKEv2 traffic to known, trusted peer IP addresses only.
Exploitation status
Public Exploit Available: Yes, multiple public proof of concept repositories exist, including those referenced in the enrichment data.
Analyst recommendation
Due to the critical nature of this vulnerability and confirmed active exploitation, immediate patching is mandatory. Organizations must prioritize the deployment of the specified Fireware OS updates across all Firebox appliances to prevent unauthorized access and potential system takeover. Failure to act promptly significantly increases the risk of a successful breach.
More WatchGuard CVEs
Sources
Originally found and disclosed by Discovered internally by WatchGuard, per the CVE Program record.