CRITICAL🚩 CISA KEV⚡ EXPLOIT✓ PATCH🇵🇱 Wersja polska

CVE-2025-14733

CVSS 9.3v4.0pub. 2025-12-19upd. 2026-08-11

An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer. If the Firebox was previously configured with the mobile user VPN with IKEv2 or a branch office VPN using IKEv2 to a dynamic gateway peer, and both of those configurations have since been deleted, that Firebox may still be vulnerable if a branch office VPN to a static gateway peer is still configured.

🤖 AI Analysis
How it works

The vulnerability is a buffer overflow (out-of-bounds write, CWE-787) in the IKEv2 protocol handler component. The vulnerability is triggered by both Mobile User VPN with IKEv2 and Branch Office VPN with IKEv2 configured with a dynamic gateway peer. An attacker can send specially crafted IKEv2 packets without prior authentication, leading to memory corruption and potential device takeover.

Impact

An attacker can execute arbitrary code on the device with the privileges of the VPN handling process, which in practice means complete takeover of the edge device and control over network traffic protected by the WatchGuard Firebox.

Mitigation & patch

Fireware OS must be immediately updated to a version higher than 11.12.4_Update1 (for 11.x branch), higher than 12.11.5 (for 12.x branch), or higher than 2025.1.3 (for 2025.1 branch), in accordance with the official WatchGuard PSIRT message (WGSA-2025-00027). Until the patch is applied, consider disabling the IKEv2 VPN function or restricting access to IKEv2 ports only to trusted IP addresses at the firewall level.

Who is affected

WatchGuard Firebox T70, M440, M370, M690, M470 running Fireware OS versions: 11.10.2 through 11.12.4_Update1 inclusive, 12.0 through 12.11.5 inclusive, and 2025.1 through 2025.1.3 inclusive, when Mobile User VPN with IKEv2 or Branch Office VPN with IKEv2 with dynamic gateway peer is configured.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Red
  • Watchguard Fireboxcloud

    HW
    Watchguard
    all versions
  • Watchguard Firebox M270

    HW
    Watchguard
    all versions
  • Watchguard Firebox M290

    HW
    Watchguard
    all versions
  • Watchguard Firebox M295

    HW
    Watchguard
    all versions
  • Watchguard Firebox M370

    HW
    Watchguard
    all versions
  • Watchguard Firebox M390

    HW
    Watchguard
    all versions
  • Watchguard Firebox M395

    HW
    Watchguard
    all versions
  • Watchguard Firebox M440

    HW
    Watchguard
    all versions
  • Watchguard Firebox M4600

    HW
    Watchguard
    all versions
  • Watchguard Firebox M470

    HW
    Watchguard
    all versions
  • Watchguard Firebox M4800

    HW
    Watchguard
    all versions
  • Watchguard Firebox M495

    HW
    Watchguard
    all versions
  • Watchguard Firebox M5600

    HW
    Watchguard
    all versions
  • Watchguard Firebox M570

    HW
    Watchguard
    all versions
  • Watchguard Firebox M5800

    HW
    Watchguard
    all versions
  • Watchguard Firebox M590

    HW
    Watchguard
    all versions
  • Watchguard Firebox M595

    HW
    Watchguard
    all versions
  • Watchguard Firebox M670

    HW
    Watchguard
    all versions
  • Watchguard Firebox M690

    HW
    Watchguard
    all versions
  • Watchguard Firebox M695

    HW
    Watchguard
    all versions
  • Watchguard Firebox Nv5

    HW
    Watchguard
    all versions
  • Watchguard Firebox T115 W

    HW
    Watchguard
    all versions
  • Watchguard Firebox T125

    HW
    Watchguard
    all versions
  • Watchguard Firebox T125 W

    HW
    Watchguard
    all versions
  • Watchguard Firebox T145

    HW
    Watchguard
    all versions
  • Watchguard Firebox T145 W

    HW
    Watchguard
    all versions
  • Watchguard Firebox T15

    HW
    Watchguard
    all versions
  • Watchguard Firebox T185

    HW
    Watchguard
    all versions
  • Watchguard Firebox T20

    HW
    Watchguard
    all versions
  • Watchguard Firebox T25

    HW
    Watchguard
    all versions

CISA KEV — detailsi

Vendori
WatchGuard
Producti
Firebox
Added to KEVi
December 19, 2025
Remediation deadline (US Federal)i
December 26, 2025(overdue)
Required action (CISA)i

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CISA descriptioni

WatchGuard Fireware OS iked process contains an out of bounds write vulnerability in the OS iked process. This vulnerability may allow a remote unauthenticated attacker to execute arbitrary code and affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
CISA DEADLINE: 26 grudnia 2025
Tags
RCEAuth BypassMemoryVPN
CWE
References

Related vulnerabilities

CVE-2025-9242CRITICAL9.3⚠ KEVsame product

An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthentic...

CVE-2022-26318CRITICAL9.8⚠ KEVPL ✓same product

RCE bez uwierzytelnienia w WatchGuard Firebox i XTM (FBX-22786)

CVE-2026-13368CRITICAL9.2same product

WatchGuard Fireware OS contains a race condition leading to a use-after-free vulnerability in LDAP authenticat...

CVE-2022-31789CRITICAL9.8PL ✓same product

Integer overflow w WatchGuard Firebox/XTM umożliwiający RCE bez uwierzytelnienia

CVE-2022-25361CRITICAL9.1PL ✓same product

WatchGuard Firebox/XTM – zdalne usuwanie plików bez uwierzytelnienia