
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14733 is a critical out-of-bounds write vulnerability in WatchGuard Fireware OS that allows remote unauthenticated attackers to execute arbitrary code. It affects the Mobile User VPN with IKEv2 and Branch Office VPN using IKEv2 when configured with a dynamic gateway peer. Affected versions include Fireware OS 11.10.2 through 11.12.4_Update1, 12.0 through 12.11.5, and 2025.1 through 2025.1.3. The vulnerability was publicly disclosed and added to the CISA KEV catalog on December 19, 2025, with a due date of December 26, 2025 (CISA KEV, WatchGuard Advisory). It carries a CVSS v3.1 base score of 9.8 (Critical) and a CVSS v4.0 base score of 9.3 (Critical) (WatchGuard Advisory).
The vulnerability is classified as CWE-787 (Out-of-bounds Write) and resides in the iked (IKE daemon) process within WatchGuard Fireware OS (CISA KEV). An attacker can send specially crafted IKEv2 packets to the affected VPN endpoint — either Mobile User VPN or Branch Office VPN configured with a dynamic gateway peer — triggering a memory write beyond the bounds of an allocated buffer, which can lead to arbitrary code execution (WatchGuard Advisory). No authentication, user interaction, or special privileges are required; the attack vector is entirely network-based with low complexity (Feedly). Technical analysis and PoC code have been published on GitHub, and Horizon3.ai has released detailed attack research (Horizon3.ai).
Successful exploitation grants a remote unauthenticated attacker full arbitrary code execution on the affected WatchGuard Firebox device, effectively resulting in complete system compromise of critical network perimeter infrastructure (WatchGuard Advisory). An attacker who gains control of a firewall device can intercept, modify, or disrupt all network traffic passing through it, enabling lateral movement into protected internal networks, data theft, and service disruption (Feedly). Over 115,000 WatchGuard Firebox devices were identified as externally accessible and potentially vulnerable, representing a massive attack surface across enterprise and SMB environments (BleepingComputer).
CVE-2025-14733 is actively exploited in the wild and was added to the CISA Known Exploited Vulnerabilities (KEV) catalog on December 19, 2025, with a remediation due date of December 26, 2025 (CISA KEV). Multiple public proof-of-concept exploits are available on GitHub, including repositories at machevalia/CVE-2025-14733 and kooyaniks/CVE-2025-14733-analysis, added in early March 2026 (Feedly). A Qilin ransomware affiliate has been reported exploiting this vulnerability alongside other CVEs against U.S. organizations using Sliver C2 (Feedly). The EPSS score is approximately 0.363 (36.3%), reflecting a high probability of exploitation relative to other CVEs (Feedly).
iked process. Public PoC code (e.g., machevalia/CVE-2025-14733 on GitHub) can be referenced for payload structure.iked process processes the packet and the out-of-bounds write corrupts memory.iked process, granting the attacker control of the firewall device, enabling deployment of backdoors, C2 implants (e.g., Sliver), or further lateral movement into the protected network (WatchGuard Advisory, Horizon3.ai, CISA KEV).iked process in Fireware system logs; unexpected authentication events or VPN tunnel establishments from unrecognized peers; error messages related to memory faults in the IKE daemon.WatchGuard has released patched versions addressing CVE-2025-14733: Fireware OS 11.12.4_Update2 or later (for 11.x versions), Fireware OS 12.11.6 or later (for 12.x versions), and Fireware OS 2025.1.4 or later (for 2025.1.x versions) (WatchGuard Advisory). Organizations should apply patches immediately, prioritizing externally accessible VPN endpoints. If immediate patching is not possible, restrict network access to IKEv2 VPN endpoints from untrusted networks, disable IKEv2 VPN if not actively in use, and implement network segmentation to limit lateral movement in the event of compromise (CISA KEV). CISA also recommends checking for signs of compromise on all internet-accessible instances after applying mitigations.
WatchGuard issued an official security advisory (WGSA-2025-00027) and a blog post announcing the availability of patched Fireware versions, urging immediate updates (WatchGuard Advisory). CISA added the vulnerability to its KEV catalog on the same day as disclosure (December 19, 2025), signaling confirmed active exploitation and mandating federal agency remediation within one week (CISA KEV). Security researchers and media outlets including BleepingComputer, The Hacker News, SecurityWeek, Dark Reading, and CSO Online widely covered the vulnerability, highlighting the scale of exposure (115,000+ devices) and the severity of active exploitation (BleepingComputer). National CERTs from Canada, Australia, Hong Kong, New Zealand, and Belgium also issued advisories, reflecting the global impact of the vulnerability.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."