WatchGuard Firebox RCE flaw exploited in wild
An actively exploited out-of-bounds write flaw in WatchGuard Firebox appliances lets unauthenticated attackers run arbitrary code; IPA urges immediate patching.
Japan's IPA has issued an alert for CVE-2025-14733, an out-of-bounds write vulnerability in WatchGuard Firebox security appliances. The vendor has confirmed that exploitation of this flaw is already occurring in the wild, and successful exploitation allows an unauthenticated remote attacker to execute arbitrary code on affected devices.
WatchGuard has released fixed Fireware OS versions and IPA recommends organizations apply the update immediately following vendor guidance. Notably, Fireware OS 11.x has reached end-of-life and will not receive a patch, so IPA advises affected users to upgrade to a supported version rather than wait for a fix.
As a network security appliance often exposed to the internet, exploited Firebox devices represent a high-value entry point for attackers into enterprise networks. Given confirmed in-the-wild exploitation and the lack of authentication requirements, organizations running Firebox should prioritize patching or upgrading without delay.
Mentioned in this report
Source reporting: https://www.ipa.go.jp/security/security-alert/2025/alert20251223.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free