top of page
perceptive_background_267k.jpg

WatchGuard Fireware OS iked process contains an out of bounds write vulnerability in the OS iked process. This vulnerability may allow a remote unauthenticated …

Published:

19 December 2025 at 00:00:00

Alert date:

19 December 2025 at 19:02:17

Source:

cisa.gov

Click to open the original link from this advisory

WatchGuard Fireware OS contains an out of bounds write vulnerability in the iked process (CVE-2025-14733). The vulnerability allows remote unauthenticated attackers to execute arbitrary code on affected systems. It impacts both mobile user VPN with IKEv2 and branch office VPN using IKEv2 when configured with dynamic gateway peer. Organizations are advised to check for signs of compromise on all internet-accessible instances after applying mitigations. This is a critical vulnerability requiring immediate attention due to the remote code execution capability without authentication.

Technical details

Mitigation steps:

Affected products:

WatchGuard Fireware OS
WatchGuard Firebox

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page