Advisory addresses a critical vulnerability that could allow a remote unauthenticated attacker to execute arbitrary code
Advisory addresses a critical vulnerability that could allow a remote unauthenticated attacker to execute arbitrary code
The following platforms are known to be affected:
WatchGuard Fireware OS versions:
Exploitation of CVE-2025-9242
CVE-2025-9242 is being actively exploited and has been added to the US Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities Catalog (KEV).
Additionally, WatchGuard has added indicators of attack (IoAs) to their advisory to help device owners identify potential attempts to exploit this vulnerability against vulnerable Firebox appliances.
Active exploitation in the wild has been reported for the vulnerability CVE-2025-9242, which affects WatchGuard Firebox OS.
CVE-2025-9242 - 'Out-of-bounds Write' vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code - CVSS v4: 9.3
Affected organisations are encouraged to review the WatchGuard Security Advisory WGSA-2025-00015 page and apply the relevant security update as soon as possible.
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the Mobile User VPN with IKEv2 and the Branch Office VPN using IKEv2 when configured with a dynamic gateway peer.This vulnerability affects Fireware OS 11.10.2 up to and including 11.12.4_Update1, 12.0 up to and including 12.11.3 and 2025.1.
Last edited: 17 November 2025 10:03 am
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
