CISA KEV · catalog date Dec 19, 2025 · first observed Jul 19, 2026
Evidence dossier
CVE-2025-14733
WatchGuard Firebox iked Out of Bounds Write Vulnerability
Exploited in the wild (CISA KEV since Dec 19, 2025). WatchGuard reports CVSS 4.0 9.3. EPSS estimates 26.5% exploit likelihood as of Aug 27, 2026.
As of Aug 27, 2026
Normalized restatement
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the Mobile User VPN with IKEv2 and the Branch Office VPN using IKEv2 when configured with a dynamic gateway peer.This vulnerability affects Fireware OS 11.10.2 up to and including 11.12.4_Update1, 12.0 up to and including 12.11.5 and 2025.1 up to and including 2025.1.3.
- State
- PUBLISHED
- Published
- Dec 19, 2025
- Updated
- Feb 26, 2026
- Evidence coverage
- 96%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCAWatchGuardOriginal evidence ↗
Record text: WatchGuard Firebox iked Out of Bounds Write Vulnerability
Inspect raw assertion
- Field
container- Value
- WatchGuard Firebox iked Out of Bounds Write Vulnerability
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: WatchGuard Firebox Out of Bounds Write Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- WatchGuard Firebox Out of Bounds Write Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 26.51% probability · 97.86th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.265100000000; percentile 0.978600000000
FIRST EPSS · score date Aug 27, 2026 · 97.9th percentile · first observed Aug 27, 2026
WatchGuard · CVSS 4.0 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- None
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
WatchGuard Firebox iked Out of Bounds Write Vulnerability
Inspect raw assertion
- Field
container- Value
- WatchGuard Firebox iked Out of Bounds Write Vulnerability
WatchGuard Firebox Out of Bounds Write Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- WatchGuard Firebox Out of Bounds Write Vulnerability
26.51% probability · 97.86th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.265100000000; percentile 0.978600000000
Applicability
Cited product scope
Grouped from 6 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
35 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "11.10.2", "versionType": "semver", "lessThanOrEqual": "11.12.4+541730"}, {"status": "affected", "version": "12.0", "versionType": "semver", "lessThanOrEqual": "12.11.5"}, {"status": "affected", "version": "12.5", "versionType": "semver", "lessThanOrEqual": "12.5.14"}, {"status": "affected", "version": "2025.1", "versionType": "semver", "lessThanOrEqual": "2025.1.3"}]product-339f8e550d0a5c407fb7d7ccbe5c14951e9a0190942eb27d887ae41b907f021dLinked exactInspect raw assertion
cpe:2.3:h:watchguard:fireboxcloud:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 1 · node/1 · match 23
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9882123d-992f-4bda-8ee0-433a3af62b54
product-49de07d112f6d7174e1371178856a4debfead02cab7771c03c54e9a031cf55d6Linked exactInspect raw assertion
cpe:2.3:h:watchguard:firebox_m270:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 1 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
db00a42a-2065-4914-80ca-981e62dec2cc
product-7467a0c6c0d5804d8d13541bb0f75b4bd82f76ff0b99ec46001d4dafce30e9c7Linked exactInspect raw assertion
cpe:2.3:h:watchguard:firebox_m290:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 1 · node/1 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5fc5e2c2-b0e3-4879-9b7c-e6e84a7bec4e
product-2f43c60a5a2db1982bba85a07c5be5d2ba0b35efc042e1e38d1c315929437fe0Linked exactInspect raw assertion
cpe:2.3:h:watchguard:firebox_m370:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 1 · node/1 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
22ac145e-2f33-4c0d-aa78-080cea1980ab
product-d58c87b1ce61649f2dfa0862bcc029b85df0566bd0e48da427d63ad8bb17f158Linked exactInspect raw assertion
cpe:2.3:h:watchguard:firebox_m390:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 1 · node/1 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
80f83640-57e7-4df8-a201-e8d5722ef978
product-03c2c7d3e32aea0a717fcabb2100b9f91448d42244b6829f7de76584386ae0d4Linked exactInspect raw assertion
cpe:2.3:h:watchguard:firebox_m440:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 1 · node/1 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2f639188-7e3d-46b8-8443-5b1f32a3ec59
product-61d03a5b1f4faddc620621cc89d47219b0d17d1e4f61a5e7e04186772801f393Linked exactInspect raw assertion
cpe:2.3:h:watchguard:firebox_m4600:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 1 · node/1 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
bb643ae5-6432-474f-bcf9-7a92b907ede1
product-5015afa76e8230d673e00b79d5f40f850cf93495d4f5b3e526e16775561c79b6Linked exactInspect raw assertion
cpe:2.3:h:watchguard:firebox_m470:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 1 · node/1 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
08fc5ce7-00f5-40c4-877f-78d3df6b01dc
product-3485d30e2064e114b88862006c3f7393692a281ab78d070230f9ca4709f538dbLinked exactInspect raw assertion
cpe:2.3:h:watchguard:firebox_m4800:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 1 · node/1 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
04b14406-f7ec-4573-8af0-bccba9bd1a15
product-f652fb63fd696619073b494d5353ee517525f1aff326d8c312a00ef3a6f558b9Linked exactInspect raw assertion
cpe:2.3:h:watchguard:firebox_m5600:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 1 · node/1 · match 8
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
4d10efe3-0342-4670-ac73-011d08a4cbea
product-b2c40c6b2c6fe573f573b7eed850a0dabf38e691c0578f2e23c882a9c3b06d12Linked exactInspect raw assertion
cpe:2.3:h:watchguard:firebox_m570:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 1 · node/1 · match 9
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
68953f7a-9037-4848-9f7b-fd8e798cb761
product-a7011f83f758bc28565d438c8234e69f20f34ea798b42a4f8fbde83c8522c0cfLinked exactInspect raw assertion
cpe:2.3:h:watchguard:firebox_m5800:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 1 · node/1 · match 10
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
1a49cf31-d888-4dae-b1d4-2e4e5a98b38a
product-ce4a545245d7af2592d342a3db51721f41077b120cea0e863ee1290c7042871aLinked exactInspect raw assertion
cpe:2.3:h:watchguard:firebox_m590:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 1 · node/1 · match 11
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9f14fe4a-4c09-4b2e-8d2c-eca03fc62595
product-a65810601b5b1d1d7ad5e2dbe38304660fccfd61bd804dbd7cf349c9a5f5c8d8Linked exactInspect raw assertion
cpe:2.3:h:watchguard:firebox_m670:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 1 · node/1 · match 12
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
413cb88d-9755-43bf-9d76-4252c7151a84
product-8bec382e930b4fff95b4769383a223dd35180a7b54e357346c7c645db358a3e6Linked exactInspect raw assertion
cpe:2.3:h:watchguard:firebox_m690:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 1 · node/1 · match 13
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
902c261b-ae76-4f2a-b660-2c069692e95d
product-a1af231e695650623a5a5b409a30472ae811f7570d2c19408c1eb260e80c422eLinked exactInspect raw assertion
cpe:2.3:h:watchguard:firebox_nv5:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 1 · node/1 · match 14
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f3781d2e-80ef-4f6c-bbc3-7570940a5ebf
product-d957931a25ffcfaeeda3e1f29a6e20293f0afba12a8bc600285fedde84c0d884Linked exactInspect raw assertion
cpe:2.3:h:watchguard:firebox_t115-w:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e28f563c-bc6e-41fb-8c62-f56cc539d4dd
product-98488300a79f2dfe96744ad2774a085317b3ff15e540e15daadb42a1a7703587Linked exactInspect raw assertion
cpe:2.3:h:watchguard:firebox_t125:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2296ae00-4806-484d-bd1d-b58a8fb87ce0
product-01ff76e35c3466dec18bce6fd9117b17ee4bfa93e3cab5fb109713bc83d6d7aeLinked exactInspect raw assertion
cpe:2.3:h:watchguard:firebox_t125-w:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f9071315-92a1-45fa-a048-bb750a40ef76
product-14a0325a5da9a7d1624fd6c02c41d8bf3f90a296637baa7fef2cdc703dbc5d71Linked exactInspect raw assertion
cpe:2.3:h:watchguard:firebox_t145:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9a435f5a-752f-44d7-8083-0c2670f26689
product-19982f06ed76de658c04283ddc87b2345716a9469ba1ee33381fea07140ca260Linked exactInspect raw assertion
cpe:2.3:h:watchguard:firebox_t145-w:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
591a04f9-ff92-4484-91dc-f268805a8708
product-c8c9e7445e01f33bdad78388a23dec9e9ccc54efa9b86aec3d1985b910f3fb65Linked exactInspect raw assertion
cpe:2.3:h:watchguard:firebox_t15:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
cc78e84b-c17b-44c5-9427-5ef97b90a6ef
product-85cc86c0986a0c723e364ca7aedee25ef16b64b92b5e0603eb376cebbc8b8747Linked exactInspect raw assertion
cpe:2.3:h:watchguard:firebox_t185:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
49672197-c3fa-42a5-a550-dca5ed89d0fa
product-2c5d0f6fb5010b35352940ab7cd41f39aad228e6d36c7c9fa2c541799ccbbd68Linked exactInspect raw assertion
cpe:2.3:h:watchguard:firebox_t20:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 1 · node/1 · match 15
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
1d5fbfa4-219f-49f8-bd2c-415a621f6ed6
Affected-product evidence
Accepted scope and product mapping
1 canonical links · 1 source-reported links
vendor-0afe2030e12385af1223ee9a2cbc34de083ebd57f9dbabf60db236b619aedc57 · product-b3c858dbbd7d31323f3fab0b9d99180b38a4cf1792b04620ba1da977488196d6
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
30c86013-ee0d-44ba-98ce-a1dc680d88a1755324f4-9903-4b36-ae9f-53999d9b8ad0fb51935d-c96c-4097-a19e-1756b8b2cd95Canonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
041a02f6-6d83-4e3b-a225-a840bc6adea4Assessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:RedCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/U:RedDirect CVE/CNA normalized decisions
WatchGuard
CVSS 4.0 · Primary · Original assertion · rank 1
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/U:Red- Validation
- Valid match
- Recomputed
- 9.3
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.