{"id":"CVE-2025-14733","title":"An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code","summary":"An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office V…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-787"],"vendor":"watchguard","product":"fireware","affected":["fireware >= 11.10.2, < 12.5.15","fireware >= 11.10.2, < 12.11.6","fireware >= 2025.1, < 2025.1.4"],"patched":["fireware 2025.1.4"],"published":"2025-12-19","updated":"2026-09-09","sourceUpdated":"2026-09-09T04:17:52.700","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-14733","references":[{"url":"https://psirt.watchguard.com/CVE-2025-14733","label":"5d1c2695-1a31-4499-88ae-e847036fd7e3"},{"url":"https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2025-00027","label":"5d1c2695-1a31-4499-88ae-e847036fd7e3"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-14733","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","cve.org","in-the-wild","exploit-available","kev"],"exploited":true,"exploitAvailable":true,"ssvc":{"exploitation":"active","automatable":"yes","technicalImpact":"total","timestamp":"2025-12-19T00:00:00+00:00"},"scores":{"nvd":9.8,"cna":9.3},"epss":0.2651,"epssPercentile":0.97966,"kev":true,"kevDateAdded":"2025-12-19","kevDueDate":"2025-12-26","kevRansomware":true,"exploits":{"github":1,"githubRepos":["https://github.com/machevalia/CVE-2025-14733"],"checkedAt":"2026-09-21T15:27:12.214Z"},"zeroDay":true,"ingestedAt":"2026-08-11T16:47:03.833Z","slug":"CVE-2025-14733","body":"## Overview\n\nAn Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer.\n\nIf the Firebox was previously configured with the mobile user VPN with IKEv2 or a branch office VPN using IKEv2 to a dynamic gateway peer, and both of those configurations have since been deleted, that Firebox may still be vulnerable if a branch office VPN to a static gateway peer is still configured.\n\n## Affected\n\n- `fireware >= 11.10.2, < 12.5.15`\n- `fireware >= 11.10.2, < 12.11.6`\n- `fireware >= 2025.1, < 2025.1.4`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `fireware 2025.1.4`","depth":"hadal","depthScore":89,"depthScoreParts":{"impact":53.9,"likelihood":5.3,"exploitation":25,"ransomware":5},"changes":[{"seq":4789,"id":"CVE-2025-14733","ts":1788887206297,"field":"exploit_available","old":"false","new":"true"},{"seq":3672,"id":"CVE-2025-14733","ts":1788886323168,"field":"exploit_available","old":"true","new":"false"},{"seq":2523,"id":"CVE-2025-14733","ts":1788882992189,"field":"exploit_available","old":"false","new":"true"},{"seq":1552,"id":"CVE-2025-14733","ts":1788882404557,"field":"exploit_available","old":"true","new":"false"},{"seq":666,"id":"CVE-2025-14733","ts":1788881842293,"field":"exploit_available","old":"false","new":"true"}]}