Safeguard
Vulnerability Analysis

WatchGuard Firebox's IKEv2 VPN Bug Hit Twice, and One Is Tied to Ransomware

Two nearly identical out-of-bounds write vulnerabilities in Firebox's iked process, both CVSS 9.8, both unauthenticated remote code execution, one confirmed for ransomware.

Safeguard Research Team
4 min read

Two nearly identical out-of-bounds write vulnerabilities in WatchGuard Firebox's IKEv2 VPN handling were confirmed exploited a little over a month apart, both scoring a critical 9.8, and one of the two carries CISA's confirmed ransomware flag.

CVECVSSRansomware useAdded to KEV
CVE-2025-92429.8Unknown12 Nov 2025
CVE-2025-147339.8Known19 Dec 2025

Why these two CVEs describe almost the exact same vulnerability

The NVD descriptions for these two CVEs are, word for word, nearly identical: an out-of-bounds write in the WatchGuard Fireware OS iked process — the daemon handling IKEv2 key exchange for VPN connections — that lets a remote, unauthenticated attacker execute arbitrary code. Both affect the same two VPN configurations: mobile user VPN with IKEv2, and branch office VPN using IKEv2 against a dynamic gateway peer. Both descriptions include the identical caveat that a Firebox previously configured with either of those setups, even after that configuration has since been deleted, may still be vulnerable if any branch office VPN to a static gateway peer remains configured — meaning the exposure can persist as a residual artifact of a configuration that's no longer active.

Whether these are two distinct patches for the same underlying defect discovered separately, or two closely related bugs in the same code path found within weeks of each other, the practical outcome for a Firebox administrator is identical: unauthenticated remote code execution against a security appliance that sits at the network perimeter by definition, reachable from the internet as a matter of the product's core purpose.

What to check this week

Patch to the fixed Fireware OS version addressing both CVEs, not just one — given how closely the two descriptions match, treat this as requiring the same verification pass rather than assuming one patch covers both.

Check for the residual-configuration exposure explicitly — both advisories warn that a Firebox may remain vulnerable even after mobile user or dynamic-gateway IKEv2 VPN configurations have been deleted, if any static-gateway branch office VPN is still active. This is easy to miss during a routine configuration review.

Treat CVE-2025-14733 with elevated urgency given its confirmed ransomware association — CISA's "Known" ransomware flag on this entry means real-world ransomware operators have this exploitation path in active use, not just proof-of-concept researchers.

Inventory every Firebox appliance's VPN configuration history, not just its current state, since the vulnerability's persistence through deleted configurations means a point-in-time snapshot of "what's configured now" understates true exposure.

Why a perimeter VPN appliance bug is a different category of risk

A vulnerability in the iked process isn't a bug in some peripheral feature of Firebox — it's a bug in the exact component whose entire job is authenticating and encrypting remote access to the network the appliance protects. An unauthenticated, remote code execution flaw there means an attacker doesn't need to compromise a VPN user's credentials, phish an employee, or find some other foothold; the appliance's own key-exchange handling is the vulnerability. That collapses the distinction between "outside the network" and "inside the network" that a VPN appliance exists specifically to enforce, which is precisely the kind of vulnerability ransomware operators look for first, since it delivers initial access without needing any user interaction or stolen credentials at all.

A closing note on perimeter appliance patch discipline

Security appliances sitting at the network edge — firewalls, VPN concentrators, gateway devices — are frequently patched less aggressively than internal servers precisely because taking them offline for maintenance interrupts business connectivity, creating a perverse incentive where the devices facing the most direct internet exposure get the most conservative patch cadence. This cluster's ransomware association on CVE-2025-14733 is a concrete illustration of what that conservatism costs when the vulnerability in question is unauthenticated remote code execution rather than something requiring a more elaborate attack chain.

How Safeguard helps

Safeguard's continuous inventory tracks perimeter security appliances like WatchGuard Firebox with the same urgency as any other internet-facing asset, surfacing both the immediate patch gap and the kind of residual configuration exposure — like a deleted VPN setup still leaving a static-gateway path vulnerable — that a one-time configuration audit is likely to miss entirely.

Never miss an update

Weekly insights on software supply chain security, delivered to your inbox.

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.