CVE-2025-9242

9.5 CISA KEV

WatchGuard · Firebox

A critical out of bounds write vulnerability in the WatchGuard Fireware OS iked process allows remote unauthenticated attackers to execute arbitrary code.

Executive summary

This critical vulnerability in WatchGuard Firebox appliances is currently being exploited in the wild and allows unauthenticated remote code execution.

Vulnerability

This is an out of bounds write vulnerability (CWE-787) in the iked process, which handles IKEv2 VPN traffic. A remote, unauthenticated attacker can trigger this flaw to achieve arbitrary code execution on the appliance.

Business impact

The CVSS score of 9.5 indicates a critical severity level, reflecting the ease of exploitation and the potential for a total system compromise. Successful exploitation grants an attacker full control over the perimeter security device, which may lead to unauthorized network access, data exfiltration, and the ability to intercept or manipulate internal traffic. The inclusion of this vulnerability in the CISA KEV catalog confirms that threat actors are actively leveraging this flaw to target organizations.

Remediation

Immediate Action: Update all affected Firebox appliances to the patched firmware versions: Fireware OS 2025.1.1, 12.11.4, 12.5.13, or 12.3.1+722811 immediately.

Proactive Monitoring: Monitor firewall logs for unexpected restarts of the iked process or unauthorized IKEv2 connection attempts from unknown sources.

Compensating Controls: If immediate patching is not possible, disable IKEv2 VPN configurations and restrict management access to the appliance to trusted internal IP addresses only.

Exploitation status

Public Exploit Available: Yes, multiple public proofs of concept and scanning scripts are available on GitHub.

Analyst recommendation

Given the active exploitation and the critical nature of this remote code execution vulnerability, organizations must treat the remediation of CVE-2025-9242 as a top priority. Administrators should verify their current firmware versions against the provided list and apply the necessary updates without delay to prevent unauthorized access to their network infrastructure.

More WatchGuard CVEs

Sources

Originally found and disclosed by btaol, per the CVE Program record.