Skip to content
COOEY

FAIL › dossier

Firebox

PRODUCT

· dossier confidence 20%

Firebox is WatchGuard's flagship firewall appliance, but its security posture is compromised by a pattern of high-severity remote code execution vulnerabilities in its IKEv2 VPN processes. These unpatched flaws allow unauthenticated attackers to execute arbitrary code, posing a critical risk to network security.

PROFILE
CategoryNetwork SecurityWhat they doFirebox is a network security firewall appliance manufactured by WatchGuard Technologies. Websitehttps://www.watchguard.com ↗
SECURITY POSTURE

The Firebox product line has a documented history of high-severity remote code execution (RCE) vulnerabilities in its IKEv2 VPN processes, indicating potential weaknesses in its core networking stack and patch management.

Notable failures
  • CVE-2025-14733: Unpatched OOBW RCE in IKEv2 VPN process
  • CVE-2025-9242: Unauthenticated RCE in iked process
Patterns: Repeated high-severity RCE vulnerabilities in VPN/ike processes; Unpatched vulnerabilities allowing remote code execution
FAILURE HISTORY · 2
DATEEVENTSEVSUMMARY
2025-12-19 CVE-2025-14733 high WatchGuard Firebox suffered an unpatched OOBW vulnerability allowing remote code execution through the IKEv2 VPN process.
2025-11-12 CVE-2025-9242 high WatchGuard Firebox OS iked process allowed remote unauthenticated attackers to execute arbitrary code
Open questions: Exact founding year of WatchGuard Technologies · Current ownership structure of WatchGuard Technologies
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-15 04:01:40.536232+00:00