CVE-2025-14733
WatchGuard Firebox / XTM (Fireware) · Firewalls, VPNs and remote access
WatchGuard Firebox Out of Bounds Write Vulnerability
At a glance
Exploited. Added to CISA’s catalog of exploited vulnerabilities on December 19, 2025.
Used in ransomware attacks, according to CISA.
Affected product: WatchGuard Firebox / XTM (Fireware) (category Firewalls, VPNs and remote access, indicative classification). Name in CISA’s catalog: WatchGuard Firebox.
What should I do?
Apply the patches or mitigations from WatchGuard; if none are available, stop using the product. For cloud services, follow the guidance from WatchGuard.
Deadline set by CISA for US federal agencies: 7 days (due December 26, 2025). It only binds those agencies, but it is a useful measure of urgency.
- WatchGuard security advisories page (general page, not the advisory for this vulnerability)
- The vendor’s specific advisory is listed in the NVD references: CVE-2025-14733 on the NVD website.
Original text of the required action (CISA)
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Timeline
- Vulnerability published Publication date (NVD)
- Exploitation confirmed Added to CISA’s KEV catalog
- CISA deadline Remediation deadline set for US federal agencies
The facts, with their sources
- Exploitation confirmed
- Yes, on December 19, 2025 Date added to the catalog of exploited vulnerabilities. Exploitation itself may have started earlier. Source: KEV catalog, collected September 29, 2026 at 14:57 UTC
- Ransomware
- Known use Source: KEV catalog, collected September 29, 2026 at 14:57 UTC
- Hunt for compromise
- Not requested by CISA Source: KEV catalog, collected September 29, 2026 at 14:57 UTC
- CISA required action
- Apply the patches or mitigations from WatchGuard; if none are available, stop using the product. For cloud services, follow the guidance from WatchGuard. Rewritten by this site from CISA’s original text. Source: KEV catalog, collected September 29, 2026 at 14:57 UTC
- CISA deadline
- December 26, 2025, 7 days Set for US federal agencies: a measure of urgency, not an obligation elsewhere. Source: KEV catalog, collected September 29, 2026 at 14:57 UTC
- Vulnerability published
- December 19, 2025 Source: National Vulnerability Database (NVD), collected September 29, 2026 at 15:00 UTC
- Product according to CISA
- WatchGuard Firebox Filed by this site under “Firewalls, VPNs and remote access” (indicative classification). Source: KEV catalog, collected September 29, 2026 at 14:57 UTC
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Technical detail of the score: attack vector, complexity, impact. Source: National Vulnerability Database (NVD), collected September 29, 2026 at 15:00 UTC
Severity and activity
FIRST’s EPSS model. Since exploitation is already confirmed, this figure is mostly useful to compare activity. Collected Sep 29, 2026.
Description
An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer. If the Firebox was previously configured with the mobile user VPN with IKEv2 or a branch office VPN using IKEv2 to a dynamic gateway peer, and both of those configurations have since been deleted, that Firebox may still be vulnerable if a branch office VPN to a static gateway peer is still configured.
Official description from the NVD, collected Sep 29, 2026. CVE® description © The MITRE Corporation.
WatchGuard Fireware OS iked process contains an out of bounds write vulnerability in the OS iked process. This vulnerability may allow a remote unauthenticated attacker to execute arbitrary code and affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer.
Summary from CISA (KEV catalog).
CERT-FR advisories
No advisory among the latest CERT-FR publications this site follows. That does not mean there are none.
Information reused under the Open Licence 2.0 (Etalab); the date of last update is shown for each advisory. This site is neither affiliated with nor endorsed by ANSSI.
Sources for this page
- CISA KEV catalog: exploitation, date added, required action, deadline, ransomware.
- NVD (NIST): CVSS severity, publication date, description, vendor references.
- EPSS (FIRST): probability of exploitation.
- CERT-FR: advisories and alerts (in French).
- Brand and category: indicative classification by this site (method).