WatchGuard Firebox
CVE-2025-14733
WatchGuard Fireware OS iked process contains an out of bounds write vulnerability in the OS iked process. This vulnerability may allow a remote unauthenticated attacker to execute arbitrary code and affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer.
What this means for your business
- It affects WatchGuard Firebox. It matters if your company, or a supplier that handles your data, runs it.
- Attackers are already using it. CISA added it to its list of flaws used in real attacks on 19 December 2025.
- Ransomware gangs are known to have used it.
- An attacker can use it remotely, over a network, without a login, and without anyone at your company clicking anything.
- FIRST's prediction model gives it a 27% chance of attack attempts being seen in the next 30 days, ranking above 97% of all known flaws.
What to do
- 1Check whether your company or your suppliers run WatchGuard Firebox, and which version. The affected versions are listed further down this page.
- 2If you do, apply the vendor's fix. A patch or vendor advisory has been published.
- 3Treat it as urgent. US federal agencies must fix it by 26 December 2025. That deadline does not apply to private companies, but it shows how seriously CISA takes it.
- 4Because attackers have used it, check the affected systems for signs of a break-in, not only for the update.
Not sure if your company is exposed?
Fastnexa’s certified penetration testers can check whether attackers could use this flaw, or others like it, against your websites, apps and network. The full test is free for our first 10 founding clients until 31 December 2026.
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA’s wording, unedited.
Scoring
- CVSS
- 9.8 (v3.1)
- Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- CVSS v4
- 9.3
- Weakness
- CWE-787
- Assigned by
- 5d1c2695-1a31-4499-88ae-e847036fd7e3
Dates
- Published
- 2025-12-19
- Last modified
- 2026-09-09
- Added to KEV
- 2025-12-19
- Remediation due
- 2025-12-26
- Sources
- CISA KEV, NVD
Affected products
- Watchguard Fireware11.10.2 - 12.5.15, 11.10.2 - 12.11.6, 2025.1 - 2025.1.4
- Watchguard Firebox T15all versions
- Watchguard Firebox T35all versions
- Watchguard Firebox M270all versions
- Watchguard Firebox M290all versions
- Watchguard Firebox M370all versions
- Watchguard Firebox M390all versions
- Watchguard Firebox M440all versions
- Watchguard Firebox M4600all versions
- Watchguard Firebox M470all versions
- Watchguard Firebox M4800all versions
- Watchguard Firebox M5600all versions
As listed in the NVD configuration data. Not a statement about your estate.