Vulnerability Description
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the Mobile User VPN with IKEv2 and the Branch Office VPN using IKEv2 when configured with a dynamic gateway peer.This vulnerability affects Fireware OS 11.10.2 up to and including 11.12.4_Update1, 12.0 up to and including 12.11.5 and 2025.1 up to and including 2025.1.3.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Watchguard | Fireware | >= 11.10.2, < 12.5.15 |
| Watchguard | Firebox T15 | All versions |
| Watchguard | Firebox T35 | All versions |
| Watchguard | Firebox M270 | All versions |
| Watchguard | Firebox M290 | All versions |
| Watchguard | Firebox M370 | All versions |
| Watchguard | Firebox M390 | All versions |
| Watchguard | Firebox M440 | All versions |
| Watchguard | Firebox M4600 | All versions |
| Watchguard | Firebox M470 | All versions |
| Watchguard | Firebox M4800 | All versions |
| Watchguard | Firebox M5600 | All versions |
| Watchguard | Firebox M570 | All versions |
| Watchguard | Firebox M5800 | All versions |
| Watchguard | Firebox M590 | All versions |
| Watchguard | Firebox M670 | All versions |
| Watchguard | Firebox M690 | All versions |
| Watchguard | Firebox Nv5 | All versions |
| Watchguard | Firebox T20 | All versions |
| Watchguard | Firebox T25 | All versions |
Related Weaknesses (CWE)
References
- https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2025-00027Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-US Government Resource
FAQ
What is CVE-2025-14733?
CVE-2025-14733 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the Mobile User VPN with IKEv2 and...
How severe is CVE-2025-14733?
CVE-2025-14733 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-14733?
Check the references section above for vendor advisories and patch information. Affected products include: Watchguard Fireware, Watchguard Firebox T15, Watchguard Firebox T35, Watchguard Firebox M270, Watchguard Firebox M290.