VORANT. Threat Intelligence Sign in Get the full feed

WatchGuard Firebox RCE flaw exploited in wild

high vulnerability

An actively exploited out-of-bounds write flaw in WatchGuard Firebox appliances lets unauthenticated attackers run arbitrary code; IPA urges immediate patching.

Japan's IPA has issued an alert for CVE-2025-14733, an out-of-bounds write vulnerability in WatchGuard Firebox security appliances. The vendor has confirmed that exploitation of this flaw is already occurring in the wild, and successful exploitation allows an unauthenticated remote attacker to execute arbitrary code on affected devices.

WatchGuard has released fixed Fireware OS versions and IPA recommends organizations apply the update immediately following vendor guidance. Notably, Fireware OS 11.x has reached end-of-life and will not receive a patch, so IPA advises affected users to upgrade to a supported version rather than wait for a fix.

As a network security appliance often exposed to the internet, exploited Firebox devices represent a high-value entry point for attackers into enterprise networks. Given confirmed in-the-wild exploitation and the lack of authentication requirements, organizations running Firebox should prioritize patching or upgrading without delay.

Mentioned in this report

Vulnerabilities CVE-2025-14733KEV

Source reporting: https://www.ipa.go.jp/security/security-alert/2025/alert20251223.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free