WatchGuard Firebox firewalls under attack (CVE-2025-14733)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-14733 | Unauthenticated Out-of-Bounds Write RCE in WatchGuard Fireware OS CVE-2025-14733 is an out-of-bounds write (CWE-787) in the iked process of WatchGuard Fireware OS on Firebox appliances, allowing a remote, unauthenticated attacker to execute arbitrary code. The flaw is reachable when the appliance is configured for Mobile User VPN with IKEv2 or a branch office VPN (BOVPN) using IKEv2 with a dynamic gateway peer; a Firebox may also remain vulnerable if those IKEv2 configurations were previously set up and then deleted while a BOVPN to a static gateway peer is still configured. Successful exploitation gives an attacker arbitrary code execution on the firewall itself, a high-value network position that can be used for further lateral movement. Affected deployments are WatchGuard Firebox appliances running Fireware OS with the described IKEv2 VPN configurations, since the IKEv2 service by definition listens on the external interface. The vulnerability is under active exploitation: it was added to CISA's KEV catalog on 2025-12-19 with known ransomware use, carries an EPSS probability of 26.5% (98th percentile) of exploitation within 30 days, and no public proof-of-concept is currently known. Do: Upgrade affected Firebox appliances to the patched Fireware OS builds identified in WatchGuard's security advisory, per CISA KEV required action and applicable BOD 22-01 guidance. Audit configurations for Mobile User VPN with IKEv2 and BOVPN IKEv2 with a dynamic gateway peer, including appliances where those settings were deleted but a BOVPN to a static gateway peer is still configured, as these may remain vulnerable. Until patched, restrict IKEv2 traffic (UDP 500/4500) to trusted source addresses or discontinue use if mitigations are unavailable. | 9.3 | 27% | KEV ransomware |
| largeplausibly in the tens of thousands of internet-exposed Firebox appliances (order of magnitude 10^4 to 10^5); unknown precisely | |
| CVE-2025-9242 | Out-of-Bounds Write in WatchGuard Fireware OS iked Enables Unauthenticated RCE WatchGuard Fireware OS contains an out-of-bounds write (CWE-787) in the iked process that a remote, unauthenticated attacker can trigger to execute arbitrary code on the appliance. The flaw is reachable via the mobile user VPN with IKEv2 and via branch office VPNs using IKEv2 to a dynamic gateway peer; devices whose IKEv2 configurations were deleted may remain vulnerable if a branch office VPN to a static gateway peer is still configured. Successful exploitation yields full system compromise, reflected in the CVSS v4.0 base score of 9.3 (network vector, no privileges or user interaction, high impact on confidentiality, integrity and availability). WatchGuard Firebox appliances with IKEv2 VPN services are affected, with public reporting citing roughly 54,000 internet-exposed Fireboxes; the issue was added to CISA's Known Exploited Vulnerabilities catalog on 2025-11-12, a public proof-of-concept exploit exists, and headlines indicate use in ransomware attacks (KEV ransomware field is listed as unknown). EPSS assigns a 91.3% probability of exploitation within 30 days (100th percentile), so remediation urgency is high. Do: Apply the patched Fireware OS release per WatchGuard's security advisory immediately (exact fixed version numbers are not provided in the source data); the KEV listing makes BOD 22-01 remediation timelines mandatory for U.S. federal agencies. As an interim mitigation, restrict or disable IKEv2 VPN exposure — mobile user VPN with IKEv2 and branch office VPN IKEv2, including residual static-peer BOVPN configurations on devices that previously had IKEv2 configured — to trusted sources only. Administrators should audit configuration history to identify Fireboxes with prior IKEv2 mobile VPN or dynamic-peer BOVPN setups, since these may remain vulnerable even after the configs were deleted. | 9.3 | 91% | KEV PoC |
| large≈54,000 internet-exposed Fireboxes (public scan figure cited in coverage) |
Full article519 words · extracted from helpnetsecurity.com · click to collapse
More than 115,000 internet-facing WatchGuard Firebox firewalls may be vulnerable to compromise via CVE-2025-14733, a remote code execution vulnerability actively targeted by attackers, Shadowserver’s latest scanning reveals.

About CVE-2025-14733
WatchGuard Firebox firewalls, which also incorporate VPN and unified threat management capabilities, are used by organizations around the world. The appliances run the Fireware OS, a network security operating system built on a hardened Linux-based kernel.
WatchGuard disclosed CVE-2025-14733 on December 18, when it also revealed “threat actors are attempting to exploit this vulnerability as part of a wider attack campaign against edge networking equipment and exposed infrastructure from multiple vendors.”
CVE-2025-14733 is an Out-of-bounds Write vulnerability in the Fireware OS’ IKED process, i.e., the IKE daemon that negotiates, authenticates, and manages VPN tunnels.
The flaw can be triggered by remote, unauthenticated attackers and may allow them to execute arbitrary code, with no user action required.
CVE-2025-14733 affects Fireware OS v2025.1, v12.x, v12.5.x (on T15 & T35 models), v12.3.1 (FIPS-certified release), and v11.x.
“This vulnerability affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer. If the Firebox was previously configured with the mobile user VPN with IKEv2 or a branch office VPN using IKEv2 to a dynamic gateway peer, and both of those configurations have since been deleted, that Firebox may still be vulnerable if a branch office VPN to a static gateway peer is still configured,” WatchGuard warned.
CVE-2025-14733 strongly resembles CVE-2025-9242, another Firewire OS pre-auth RCE flaw that’s been exploited by attackers this year.
What to do?
The US Cybersecurity and Infrastructure Security Agency added CVE-2025-14733 to its Known Exploited Vulnerabilities catalog and has ordered US federal civilian agencies to remediate it by December 26.
Users have been urged to upgrade to a Fireware OS version – v2025.1.4, v12.11.6, v12.5.15 or 12.3.1_Update4 (B728352) – and to check for indicators of compromise.
WatchGuard shared four IP addresses associated with known threat actor activity, as well as log messages that could point to attackers having targeted their device.
“During a successful exploit, the IKED process (responsible for handling IKE negotiations) will hang, interrupting VPN tunnel negotiations and re-keys. This is a strong indicator of attack. Existing tunnels may continue to pass traffic,” the company explained.
“After a failed or successful exploit, the IKED process will crash and generate a fault report on the Firebox. Be aware, there are other situations that could cause the IKED process to crash. This is a weak indicator of attack.”
Customers who find evidence of compromise should update the OS and immediately rotate all secrets locally stored on the device(s).
“If your Firebox is only configured with Branch Office VPN tunnels to static gateway peers and you are not able to immediately upgrade the device to a version of Fireware OS with the vulnerability resolution, you can follow WatchGuard’s recommendations for Secure Access to Branch Office VPNs that Use IPSec and IKEv2 as a temporary workaround,” the company concluded.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/12/22/watchguard-firebox-vulnerability-cve-2025-14733/