logo

CVE-2025-14733 Vulnerability: WatchGuard Addresses a Critical RCE Affecting Firebox Firewalls, Actively Exploited for Real-World Attacks

ID: 1c98d097-f423-596a-a373-37061291862b

STIX ID: report--1c98d097-f423-596a-a373-37061291862b

Feed Name: SOC Prime Blog

Threat Score
88/100

Date Published: 2025-12-23

Date Updated: 2026-04-30

Author: Daryna Olyniychuk

...
...

WatchGuard disclosed CVE-2025-14733, a critical (CVSS 9.3) out-of-bounds write in the iked process of Fireware OS that enables unauthenticated remote code execution against IKEv2 VPN configurations; the flaw is being actively exploited in the wild, CISA added it to the KEV catalog, Shadowserver identified ~117,490 exposed devices, and WatchGuard published fixes, IoAs (including specific IPs and oversized IKE_AUTH CERT payloads), and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.