WatchGuard Zero-Day Actively Exploited to Seize Control of Firewalls
WatchGuard has issued an alert about a critical zero-day vulnerability in its Firebox firewall appliances, identified as CVE-2025-14733. This flaw enables remote attackers to control affected devices without authentication.
WatchGuard has issued an alert about a critical zero-day vulnerability in its Firebox firewall appliances, identified as CVE-2025-14733. This flaw enables remote attackers to control affected devices without authentication.
The vulnerability is an Out-of-Bounds Write issue within the iked process, which manages IKEv2 VPN negotiations. It affects Firebox appliances configured for:
Mobile user VPNs using IKEv2. Branch office VPNs using IKEv2 with a dynamic gateway peer.
This vulnerability allows attackers to send crafted requests to the firewall, causing a memory corruption error. Successful exploitation can result in arbitrary code execution, enabling attackers to execute malicious commands, install malware, or gain full administrative control.
Feature Details
CVE ID CVE-2025-14733
WatchGuard has issued an alert about a critical zero-day vulnerability in its Firebox firewall appliances, identified as CVE-2025-14733.
Vulnerability Type Out-of-Bounds Write ( iked process)
Impact Critical (Remote Code Execution)
CVSS Score 9.3 (Critical)
WatchGuard has verified that this vulnerability is actively being exploited. Even if a vulnerable VPN configuration has been deleted, risk remains if a static branch office VPN is still configured. Administrators should inspect logs for indicators of compromise, such as iked process crashes or hangs, and specific log messages like "Invalid peer certificate chain" or "Abnormally large IKE_AUTH request CERT payload" exceeding 2000 bytes.
Malicious activity has been linked to the following IP addresses:
45.95.19[.]50 51.15.17[.]89 172.93.107[.]67 199.247.7[.]82
To address this issue, WatchGuard has released software updates. Administrators should upgrade to Fireware OS 2025.1.4, 12.11.6, or 12.5.15 immediately. If a device may have been compromised, it is crucial to rotate all locally stored secrets after applying the patch.
Based on reporting by GBHackers.
