# WatchGuard Firebox RCE under active exploit

Published: 2025-12-22 · Severity: critical
Canonical: https://vorant.io/reports/3278b391-d170-51bb-8b73-06bf7f48f77a/watchguard-firebox-rce-under-active-exploit

> CVE-2025-14733, an out-of-bounds write flaw in WatchGuard Firebox appliances, is being actively exploited for unauthenticated remote code execution.

Japan's IPA has issued an advisory for CVE-2025-14733, an out-of-bounds write vulnerability in WatchGuard Firebox security appliances. The flaw allows unauthenticated remote attackers to execute arbitrary code on affected devices. WatchGuard Technologies has confirmed active exploitation of this vulnerability in the wild.

The vendor has released patches for Fireware OS version 12 and 13 series. Organizations running Fireware OS 11, which has reached end-of-life, are urged to upgrade immediately as no patches will be issued for that version. IPA warns that the threat may expand and recommends immediate patching following the vendor's published procedures.

## Mentioned in this report

- Vulnerabilities: CVE-2025-14733 (KEV)

Source reporting: https://www.ipa.go.jp/security/security-alert/2025/alert20251223.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/3278b391-d170-51bb-8b73-06bf7f48f77a/watchguard-firebox-rce-under-active-exploit.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
