CVE-2025-14733
WatchGuard Firebox iked Out of Bounds Write Vulnerability
In short
A critical flaw in WatchGuard Firebox allows attackers to write data outside safe memory boundaries through the VPN service, potentially letting them run malicious code on the device without needing a password. This affects multiple versions of Fireware OS.
Technical detail
Out-of-bounds write vulnerability in the IKEv2 daemon (iked) affecting Mobile User VPN and Branch Office VPN configurations with dynamic gateway peers. Remote unauthenticated attackers can exploit memory corruption to achieve arbitrary code execution; affects Fireware OS versions 11.10.2–11.12.4_Update1, 12.0–12.11.5, and 2025.1–2025.1.3.
Summary generated and translated by AI from the official description.
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the Mobile User VPN with IKEv2 and the Branch Office VPN using IKEv2 when configured with a dynamic gateway peer.This vulnerability affects Fireware OS 11.10.2 up to and including 11.12.4_Update1, 12.0 up to and including 12.11.5 and 2025.1 up to and including 2025.1.3.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/U:Red
Affected products
WatchGuard · Fireware OSpublic PoCs found — 1
githubgithub.com/machevalia/CVE-2025-14733★ 0⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →