WatchGuard CVE-2025-14733 is a critical out-of-bounds write vulnerability in the Fireware OS iked process. It can allow an unauthenticated remote attacker to execute arbitrary code on affected Firebox appliances with certain IKEv2 VPN configurations.
WatchGuard disclosed the flaw and released fixes in December 2025. CISA added it to its Known Exploited Vulnerabilities catalog and later marked it as known to be used in ransomware campaigns. However, no ransomware group or complete attack chain has been publicly identified.
Organizations should install the appropriate Fireware OS update, examine affected appliances for exploitation indicators, and rotate locally stored secrets if compromise is suspected. Effective remediation requires dual action: patching the Firebox at the network edge and using UEM and XDR to contain lateral movement on downstream endpoints. Hexnode UEM can strengthen downstream endpoint posture, while Hexnode XDR can help detect and contain related malicious activity on Windows and macOS endpoints.
Introduction
Applying a firewall patch may not be enough if attackers accessed the appliance before the update.
WatchGuard CVE-2025-14733 affects the iked process in Fireware OS. The vulnerability can enable unauthenticated remote code execution when a vulnerable Firebox processes malicious IKEv2 traffic.
WatchGuard disclosed the flaw on December 19, 2025, after observing attempted exploitation. In September 2026, CISA marked the vulnerability as known to be used in ransomware campaigns. That update raises the priority from routine patch management to compromise assessment and ransomware response.
Attackers may also exfiltrate Firebox configuration data and local management information. Therefore, organizations must consider the possibility that secrets or network details remained exposed even after installing the firmware fix.
Who is WatchGuard?
WatchGuard Technologies develops network security products for businesses and managed service providers. Its Firebox appliances provide firewall, VPN, traffic inspection, and other network-edge security functions through the Fireware OS platform.
These appliances often sit between internal systems and external networks, making their configurations sensitive. A Firebox configuration may contain information about VPN connections, security policies, network routes, and locally stored secrets. If exfiltrated, these configuration files can expose internal IP subnets, routing tables, and pre-shared keys (PSKs), giving attackers a blueprint for downstream lateral movement.
WatchGuard is the affected vendor in this incident, not the threat actor. The organizations exploiting CVE-2025-14733 have not been publicly identified. CISA has confirmed ransomware-campaign use, but it has not named a ransomware operation, affected victim, or targeted industry.
What happened?
WatchGuard CVE-2025-14733 is an out-of-bounds write vulnerability in the Fireware OS iked process, which handles Internet Key Exchange operations for IPsec VPN connections.
Specially crafted IKEv2 input can trigger memory corruption and potentially allow an unauthenticated remote attacker to execute arbitrary code on an affected Firebox.
Incident detail
Verified information
Initial disclosure
December 19, 2025
Advisory update
August 10, 2026
CISA status
Added to the CISA KEV catalog and later marked as known to be used in ransomware campaigns
Threat actor
Unidentified threat actors; no ransomware group has been publicly named
Affected target
WatchGuard Firebox appliances running vulnerable Fireware OS versions
Initial access
Unauthenticated exploitation through affected IKEv2 VPN handling
Social engineering
None reported
Vulnerable component
Fireware OS iked process
Possible impact
Remote execution of arbitrary code on the Firebox
Observed data access
Exfiltration of the active configuration file and, in one activity variant, the local management user database
Credential or MFA impact
No confirmed MFA bypass; locally stored secrets may require rotation if compromise occurred
Persistence
No persistence technique has been publicly confirmed
Ransomware connection
CISA lists known ransomware-campaign use, but public reporting does not describe the ransomware family or subsequent encryption activity
Which Fireware OS versions are affected?
The affected versions depend on the Firebox model and release branch.
Fireware OS branch
Vulnerable versions
Fixed or unaffected versions
Default releases
2025.1 before 2025.1.4; 12.0 before 12.11.6; 11.10.2 through 11.12.4+541730
2025.1.4 or later; 12.11.6 or later; builds later than 11.12.4+541730
T15 and T35
12.0 before 12.5.15
12.5.15 or later
FIPS releases
12.0 before 12.3.1+728352
12.3.1+728352 or later
The exposure is not limited to appliances currently using Mobile User VPN with IKEv2 or Branch Office VPN with an IKEv2 dynamic gateway peer. A Firebox may remain vulnerable after administrators delete these configurations if a Branch Office VPN with a static gateway peer remains configured. Therefore, disabling Mobile User VPN with IKEv2 is not a valid workaround when a Branch Office VPN (BOVPN) with a static peer remains active, because the iked process remains exposed.
Top 7 Hexnode XDR Capabilities to Assess Before Deployment
Assess seven Hexnode XDR capabilities for stronger threat detection, investigation, and response.
What did attackers access?
WatchGuard identified two variants of post-exploitation activity against exposed appliances.
In one variant, the attacker encrypted and exfiltrated the active Firebox configuration file. In the other, the attacker created and exfiltrated a gzip archive containing the active configuration and local management user database.
Encrypting a file before exfiltration does not, by itself, confirm that ransomware encrypted systems or disrupted operations. The confirmed ransomware association comes from CISA’s campaign-use classification, while the complete intrusion sequence remains undisclosed.
Why this matters
A compromised firewall can expose more than one network device. Its configuration may help attackers understand VPN connections, internal routing, access rules, and other details useful for navigating the environment. Credential reuse further increases this risk: if exfiltrated pre-shared keys or local administrator credentials match those used by internal service accounts, attackers can pivot directly from the network edge to internal endpoints without requiring an additional exploit chain.
Firmware updates close the vulnerability, but they do not automatically determine whether attackers previously executed code or removed sensitive information. Security teams must combine patching with log review, indicator-based threat hunting, and secret rotation when exploitation is suspected. This response should include checking for credential reuse and rotating exposed pre-shared keys, local administrator credentials, and any matching internal service-account credentials.
Endpoint and identity controls also remain important. If an attacker uses information taken from the Firebox to reach internal systems, security teams need visibility beyond the network edge. Device compliance, least privilege, endpoint monitoring, and access restrictions can reduce the attacker’s ability to turn an appliance compromise into broader ransomware activity.
Hexnode UEM can provide a centralized inventory of enrolled devices, including operating-system, application, hardware, and management information. This visibility helps security teams identify endpoints connected to affected offices, VPN environments, or administrative workflows. Following a suspected Firebox compromise, teams can use this inventory to audit connected endpoints and prioritize potentially exposed devices for investigation and containment.
Administrators can create compliance policies and review devices that fall outside the organization’s approved security baseline. They can also manage operating-system and supported application patches. Advanced patch-management workflows are available for Windows and macOS, while update capabilities differ across other supported platforms. After rotating compromised VPN keys, administrators can push updated VPN client profiles and certificates to managed endpoints on supported platforms.
Application restrictions and blocklist or allowlist policies can further reduce exposure to unapproved software where the device platform and management mode support those controls. These policies can also restrict unauthorized remote-access software that attackers might use to maintain access or move laterally.
Hexnode UEM does not patch or investigate WatchGuard Firebox appliances. Its role is to improve the security posture of managed endpoints that could face downstream exposure after a network-edge compromise.
Hexnode XDR: Detect and contain Windows endpoint threats
Hexnode XDR can monitor Windows and macOS endpoints for suspicious process execution, file activity, network behavior, and system changes. Its incident views help administrators investigate detected threats and prioritize responses based on severity and context. Following a firewall breach, XDR can help detect post-exploitation indicators such as suspicious PowerShell execution on Windows, unexpected Terminal or shell activity on macOS, and unusual network connections originating from internal endpoints.
If attackers move from a compromised Firebox to Windows or macOS endpoints, security teams can use Hexnode XDR to investigate related activity. Available response actions include terminating malicious processes, quarantining detected files, and isolating affected endpoints from the network while retaining a management connection.
Hexnode XDR supports Windows and macOS endpoints. It does not directly monitor the Firebox or replace vendor-provided firmware updates, appliance forensics, network monitoring, or credential rotation.
What security teams should do next
Patch Fireware OS immediately. Identify every WatchGuard Firebox, including appliances that previously used vulnerable IKEv2 configurations, compare each device against the vendor’s affected-version guidance, and install the appropriate fixed release.
Audit active VPN and management sessions and hunt for local indicators of compromise (IoCs). Preserve and review relevant logs for abnormal IKE authentication certificate payloads, unexpected iked crashes or hangs, and connections involving published malicious infrastructure.
Rotate all secrets stored on the Firebox, including pre-shared keys, local administrator credentials, certificates, and any credentials reused by internal accounts or services. Also assess the integrity of the appliance configuration.
After rotating the keys and certificates, use Hexnode UEM to push updated VPN client profiles and certificates to managed devices and verify their compliance and patch posture.
Monitor Windows and macOS endpoints with Hexnode XDR for signs of downstream lateral movement or post-exploitation activity, and isolate affected devices when suspicious processes, files, or network connections are detected.
Try Hexnode Free for 14 Days
Strengthen endpoint security and contain ransomware risks with Hexnode.
I’m a technical content writer at Hexnode who loves simplifying tech. I break down complex ideas, remove the fluff, and help readers clearly understand our product for what it actually is: simple, reliable, and built to solve real problems.