Home ยท Wiki ยท Vulnerabilities & CVEs
type: cve ยท created: 2026-09-11 ยท updated: 2026-09-11 ยท tags: [cve, watchguard, firebox, rce, kev, active-exploitation, ransomware] ยท confidence: high ยท severity: critical ยท affected_sectors: [government, technology, smb] ยท au_impact: true

CVE-2025-14733 is a critical out-of-bounds write in WatchGuard Firebox firewalls running Fireware OS that allows unauthenticated attackers to execute malicious code remotely in low-complexity attacks. It affects Fireware OS 11.x and later (including 11.12.4_Update1), 12.x and later (including 12.11.5), and 2025.1 through 2025.1.3. Unpatched Fireboxes are exploitable where IKEv2 VPN is configured, but WatchGuard has warned that devices may still be compromised even after vulnerable configurations are deleted if a branch-office VPN to a static gateway peer remains configured. WatchGuard patched the flaw and published indicators of attack in December 2025, and CISA added it to the Known Exploited Vulnerabilities catalogue the same month with a one-week federal remediation window.

Attribute Detail
CVE CVE-2025-14733
Type Out-of-bounds write enabling unauthenticated RCE
Affected Fireware OS 11.x+, 12.x+, 2025.1โ€“2025.1.3
Exploited In the wild since December 2025; ransomware use confirmed 10 Sep 2026
Exposure 115,000+ Fireboxes exposed at disclosure; ~9,000 still unpatched Sep 2026
KEV Added December 2025; updated September 2026 for ransomware activity

On 10 September 2026 CISA updated the KEV entry to record that ransomware gangs are now exploiting the flaw, without detailing the activity. The nine-month gap between disclosure and confirmed ransomware use, against a Shadowserver count that still finds nearly 9,000 unpatched instances online, makes this a standing example of the shrinking exploitation window versus the unchanged remediation window. See also CVE-2022-23176, an earlier WatchGuard flaw exploited by Russian state hackers.