Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-14733

83
FAUCET Score

CVE-2025-14733 is a critical Out-of-bounds Write vulnerability in WatchGuard Fireware OS, affecting versions 11.10.2 through 12.11.5 and 2025.1 through 2025.1.3, specifically when Mobile User VPN or Branch Office VPN are configured with a dynamic IKEv2 gateway peer. This flaw carries a CVSS score of 9.8 (CRITICAL), allowing remote, unauthenticated attackers to execute arbitrary code with high impact on confidentiality, integrity, and availability. The vulnerability is actively exploited in the wild, as confirmed by its inclusion in the KEV catalog and significant media coverage, despite no public Metasploit or ExploitDB modules. Community discussion is also exceptionally high, indicating widespread awareness and concern.

Impacted Technologies

VendorProductVersion(s)CPE
>= 11.10.2, < 12.5.15CPE matchmatch criteria
cpe:2.3:o:watchguard:fireware:*:*:*:*:*:*:*:*
>= 11.10.2, < 12.11.6CPE matchmatch criteria
cpe:2.3:o:watchguard:fireware:*:*:*:*:*:*:*:*
>= 2025.1, < 2025.1.4CPE matchmatch criteria
cpe:2.3:o:watchguard:fireware:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

9.3CRITICAL

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Red

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
21.84%
Probability of exploitation in next 30 days
EPSS Percentile
97.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
Added to KEV · Dec 19, 2025
This CVE's current EPSS score of 0.2184 is in the 93rd percentile among its peer group of 36,829 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (6)

amazonvendor investigatingvia llm_extracted
horillavendor investigatingvia llm_extracted
inveniosoftwarevendor investigatingvia llm_extracted
jitsivendor investigatingvia llm_extracted
leantimevendor investigatingvia llm_extracted
nutanixvendor investigatingvia llm_extracted

Vendor Advisories (6)

leantimellm-leantime-949b3c0bc39e96fdCRITICAL

WatchGuard Fireware Out of Bounds Write (CVE-2025-14733)

Mar 17, 2026
amazonllm-amazon-7ce41bb78d8d6f19CRITICAL

WatchGuard Fireware Out of Bounds Write (CVE-2025-14733)

Mar 17, 2026
nutanixllm-nutanix-17b4ab36899b3faaCRITICAL

WatchGuard Fireware Out of Bounds Write (CVE-2025-14733)

Mar 17, 2026
horillallm-horilla-ed6410f214904ac7CRITICAL

WatchGuard Fireware Out of Bounds Write (CVE-2025-14733)

Mar 17, 2026
inveniosoftwarellm-inveniosoftware-068056788b6380a3CRITICAL

WatchGuard Fireware Out of Bounds Write (CVE-2025-14733)

Mar 17, 2026
jitsillm-jitsi-03eff7b300ea98f1CRITICAL

WatchGuard Fireware Out of Bounds Write (CVE-2025-14733)

Mar 17, 2026

References

cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
watchguard.com / wgrd-psirt/advisory/wgsa-2025-00027
Vendor Advisory