VORANT. Threat Intelligence Sign in Get the full feed

WatchGuard Firebox RCE under active exploit

critical vulnerability

CVE-2025-14733, an out-of-bounds write flaw in WatchGuard Firebox appliances, is being actively exploited for unauthenticated remote code execution.

Japan's IPA has issued an advisory for CVE-2025-14733, an out-of-bounds write vulnerability in WatchGuard Firebox security appliances. The flaw allows unauthenticated remote attackers to execute arbitrary code on affected devices. WatchGuard Technologies has confirmed active exploitation of this vulnerability in the wild.

The vendor has released patches for Fireware OS version 12 and 13 series. Organizations running Fireware OS 11, which has reached end-of-life, are urged to upgrade immediately as no patches will be issued for that version. IPA warns that the threat may expand and recommends immediate patching following the vendor's published procedures.

Mentioned in this report

Vulnerabilities CVE-2025-14733KEV

Source reporting: https://www.ipa.go.jp/security/security-alert/2025/alert20251223.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free