WatchGuard Firebox appliances contain an actively exploited out-of-bounds write…
WatchGuard Firebox appliances contain an actively exploited out-of-bounds write vulnerability (CVE-2025-14733) allowing unauthenticated remote code execution.
Japan's IPA has issued a security alert regarding a critical vulnerability in WatchGuard Firebox security appliances. The vulnerability, tracked as CVE-2025-14733, is an out-of-bounds write flaw that can be exploited by unauthenticated remote attackers to achieve arbitrary code execution on affected devices.
WatchGuard Technologies has confirmed that this vulnerability is being actively exploited in the wild. The vendor has released patches for Fireware OS versions 12.10.5, 12.11.5, and 12.12.1. However, Fireware OS 11.x has reached end-of-life and will not receive security updates, requiring affected organizations to upgrade to a supported version.
Given the active exploitation and the critical nature of firewall appliances in network security architecture, organizations using WatchGuard Firebox products should prioritize patching immediately. The IPA warns that damage may expand and strongly recommends following the vendor's update procedures without delay.
Mentioned in this report
Source reporting: https://www.ipa.go.jp/security/security-alert/2025/alert20251223.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free