Critical RCE Vulnerability Actively Exploited in WatchGuard Firebox Firewalls
CriticalExecutive Summary
Over 115,000 WatchGuard Firebox devices are vulnerable to a critical remote code execution (RCE) vulnerability, CVE-2025-14733, which is being actively exploited, allowing unauthenticated attackers to remotely execute arbitrary code. The vulnerability affects Firebox firewalls running Fireware OS and requires immediate patching or mitigation.
Vulnerability Details
- Affected Product: WatchGuard Firebox firewalls running Fireware OS 11.x and later (including 11.12.4_Update1), 12.x and later (including 12.11.5), and 2025.1 up to and including 2025.1.3
- Identifier: CVE-2025-14733
- CVSS Score: 9.3 (Critical)
- Exploitation Status: Actively Exploited
Risk & Impact
- Triage: Urgent; immediate patching or mitigation is required to prevent potential compromise.
- Attack Vector: The vulnerability is an out-of-bounds write in the Fireware OS IKEv2 process (iked), allowing remote, unauthenticated attackers to execute arbitrary code by sending crafted IKEv2 packets.
- Ease of Exploit: Low complexity; successful exploitation enables unauthenticated attackers to execute arbitrary code remotely on vulnerable devices without user interaction.
Action Plan
- Immediate Action: Upgrade Fireware OS to a fixed version (2025.1.4, 12.11.6, 12.5.15, or 12.3.1_Update4). Note: No patch is available for 11.x versions, which are end-of-life.
- Workaround: Disable dynamic peer BOVPNs, add new firewall policies, and disable default system policies that handle VPN traffic. If unable to patch immediately, disable Mobile User VPN with IKEv2 and BOVPNs using IKEv2 with dynamic gateway peers, or restrict IKEv2 exposure to only trusted peers.
- Detection: Monitor for anomalous VPN activity and review logs for indicators of compromise published by WatchGuard, such as abnormally large IKE_AUTH request IDi payloads or evidence of an iked process hang. Check Firebox appliances for signs of compromise, such as outbound traffic to specific IP addresses.
Relevant professional terms
- Remote Code Execution (RCE)
- A type of security vulnerability that allows an attacker to run arbitrary code on a remote machine or network. This can lead to the deployment of malware, data theft, or complete system takeover.
- Firewall
- A network security system that monitors and controls incoming and outgoing network traffic based on predetermined security rules. It establishes a barrier between a trusted internal network and untrusted external networks, preventing unauthorized access and malicious traffic.
Source: Bleeping Computer
