logo

CVE-2025-14733: WatchGuard Firebox iked Out of Bounds Write Vulnerability Exploited in the Wild

ID: 435454f4-68e5-52a1-b93e-3667fde93357

STIX ID: report--435454f4-68e5-52a1-b93e-3667fde93357

Feed Name: Arctic Wolf

Threat Score
85/100

Date Published: 2025-12-19

Date Updated: 2026-07-26

Author: Andres Ramos

...
...

On December 18, 2025, WatchGuard issued fixes for CVE-2025-14733 — a critical out-of-bounds write in the iked process of Fireware OS enabling remote unauthenticated code execution, with confirmed in-the-wild exploitation. Affected configurations include IKEv2 mobile and branch office VPNs (including some static-peer cases); Arctic Wolf recommends immediate upgrade to the listed fixed Fireware OS versions, rotation of locally stored secrets, and applying WatchGuard's temporary secure-access guidance if patching cannot be done immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.