


Perceptive Security
SOC/SIEM Consultancy

WatchGuard Fireware OS iked process contains an out of bounds write vulnerability in the OS iked process. This vulnerability may allow a remote unauthenticated …
Published:
19 december 2025 om 00:00:00
Alert date:
19 december 2025 om 19:02:17
Source:
cisa.gov
WatchGuard Fireware OS contains an out of bounds write vulnerability in the iked process (CVE-2025-14733). The vulnerability allows remote unauthenticated attackers to execute arbitrary code on affected systems. It impacts both mobile user VPN with IKEv2 and branch office VPN using IKEv2 when configured with dynamic gateway peer. Organizations are advised to check for signs of compromise on all internet-accessible instances after applying mitigations. This is a critical vulnerability requiring immediate attention due to the remote code execution capability without authentication.
Technical details
Mitigation steps:
Affected products:
WatchGuard Fireware OS
WatchGuard Firebox
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2025-14733
https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2025-00027
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
