CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

Active Exploitation of Critical WatchGuard Fireware OS VPN Vulnerability (CVE-2025-14733)

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

WatchGuard has released patches for a critical out-of-bounds write vulnerability (CVE-2025-14733, CVSS 9.3) in Fireware OS, which is being actively exploited in the wild. The flaw affects the iked process and could allow remote unauthenticated attackers to execute arbitrary code. The vulnerability impacts various versions of Fireware OS, including 2025.1, 12.x, 12.5.x, and 12.3.1, while versions 11.x are end-of-life. WatchGuard has observed active exploitation attempts from several IP addresses, some of which are linked to recent Fortinet vulnerabilities. The company has provided indicators of compromise (IoCs) and temporary mitigation steps for affected devices.

Timeline

  1. 19.12.2025 13:23 1 articles · 7h ago

    WatchGuard Releases Patches for Actively Exploited Fireware OS VPN Vulnerability

    WatchGuard has released patches for a critical out-of-bounds write vulnerability (CVE-2025-14733) in Fireware OS, which is being actively exploited. The flaw affects the iked process and allows remote unauthenticated attackers to execute arbitrary code. The company has provided IoCs and temporary mitigation steps for affected devices.

    Show sources

Information Snippets