CVE-2025-14733
Description
An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer.
If the Firebox was previously configured with the mobile user VPN with IKEv2 or a branch office VPN using IKEv2 to a dynamic gateway peer, and both of those configurations have since been deleted, that Firebox may still be vulnerable if a branch office VPN to a static gateway peer is still configured.
Summary dbcve.org
An out-of-bounds write vulnerability exists in the iked (IKE daemon) process of WatchGuard Fireware OS. This allows a remote unauthenticated attacker to achieve arbitrary code execution. The vulnerability is triggered specifically through IKEv2 configurations—either mobile user VPN or branch office VPN with a dynamic gateway peer. Notably, even if these VPN configurations have been deleted, the system remains vulnerable if a branch office VPN to a static gateway peer is still configured.
Mitigation
Apply the vendor-provided patch or firmware update for Fireware OS. Verify and remove any legacy IKEv2 VPN configurations (mobile user or dynamic gateway branch office), even if they appear deleted, and ensure only necessary static gateway VPN configurations remain.