CVE-2025-9242
An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer. If the Firebox was previously configured with the mobile user VPN with IKEv2 or a branch office VPN using IKEv2 to a dynamic gateway peer, and both of those configurations have since been deleted, that Firebox may still be vulnerable if a branch office VPN to a static gateway peer is still configured.
Actively exploited
- In the CISA exploited-vulnerabilities catalogue since Nov 12, 2025
- US federal agencies must remediate it by Dec 3, 2025 (BOD 22-01)
- First attack observed 34 days after disclosure
- Used in ransomware campaigns
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Source: CISA KEV · May 1, 2026 Jan 20, 2026 Dec 11, 2025 Dec 9, 2025 Nov 12, 2025 Oct 21, 2025
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HAffected products
| Vendors | Product | Versions |
|---|---|---|
| watchguard | fireware | < 12.11.4 |
| watchguard | firebox m270 | — |
| watchguard | firebox m290 | — |
| watchguard | firebox m370 | — |
| watchguard | firebox m390 | — |
| watchguard | firebox m440 | — |
| watchguard | firebox m4600 | — |
| watchguard | firebox m470 | — |
| watchguard | firebox m4800 | — |
| watchguard | firebox m5600 | — |
| watchguard | firebox m570 | — |
| watchguard | firebox m5800 | — |
| watchguard | firebox m590 | — |
| watchguard | firebox m670 | — |
| watchguard | firebox m690 | — |
| watchguard | firebox nv5 | — |
| watchguard | firebox t20 | — |
| watchguard | firebox t25 | — |
| watchguard | firebox t40 | — |
| watchguard | firebox t45 | — |
| watchguard | firebox t55 | — |
| watchguard | firebox t70 | — |
| watchguard | firebox t80 | — |
| watchguard | firebox t85 | — |
| watchguard | fireboxcloud | — |
Related articles
This product uses the NVD API but is not endorsed or certified by the NVD.
