Skip to content
CC-4716 - Exploitation of WatchGuard Firebox OS Vulnerability CVE-2025

CC-4716 - Exploitation of WatchGuard Firebox OS Vulnerability CVE-2025

Digital.Nhs.Uk •[email protected] (NHS Digital) • November 13, 2025

Advisory addresses a critical vulnerability that could allow a remote unauthenticated attacker to execute arbitrary code

Advisory addresses a critical vulnerability that could allow a remote unauthenticated attacker to execute arbitrary code

The following platforms are known to be affected:

WatchGuard Fireware OS versions:

Exploitation of CVE-2025-9242

CVE-2025-9242 is being actively exploited and has been added to the US Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities Catalog (KEV).

Additionally, WatchGuard has added indicators of attack (IoAs) to their advisory to help device owners identify potential attempts to exploit this vulnerability against vulnerable Firebox appliances.

Active exploitation in the wild has been reported for the vulnerability CVE-2025-9242, which affects WatchGuard Firebox OS.

CVE-2025-9242 - 'Out-of-bounds Write' vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code - CVSS v4: 9.3

Affected organisations are encouraged to review the WatchGuard Security Advisory WGSA-2025-00015 page and apply the relevant security update as soon as possible.

An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the Mobile User VPN with IKEv2 and the Branch Office VPN using IKEv2 when configured with a dynamic gateway peer.This vulnerability affects Fireware OS 11.10.2 up to and including 11.12.4_Update1, 12.0 up to and including 12.11.3 and 2025.1.

Last edited: 17 November 2025 10:03 am

Extracted Entities