{"cvss":9.3,"datePublished":"2025-12-19","dateUpdated":"2025-12-19","description":"WatchGuard Fireware OS iked process contains an out of bounds write vulnerability in the OS iked process. This vulnerability may allow a remote unauthenticated attacker to execute arbitrary code and affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer.","dueDate":"2025-12-26","id":"CVE-2025-14733","kev_catalogs":["cisa"],"knownRansomwareCampaignUse":"Known","notes":"Check for signs of potential compromise on all internet accessible instances after applying mitigations. For more information please see: https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2025-00027 ; https://nvd.nist.gov/vuln/detail/CVE-2025-14733","product":"Firebox","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","severity":"CRITICAL","source":"cisa_known_exploited","title":"WatchGuard Firebox Out of Bounds Write Vulnerability","vendor":"WatchGuard"}