Vulnerability Description
An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer. If the Firebox was previously configured with the mobile user VPN with IKEv2 or a branch office VPN using IKEv2 to a dynamic gateway peer, and both of those configurations have since been deleted, that Firebox may still be vulnerable if a branch office VPN to a static gateway peer is still configured.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Watchguard | Fireware | >= 11.10.2, < 12.11.4 |
| Watchguard | Firebox M270 | All versions |
| Watchguard | Firebox M290 | All versions |
| Watchguard | Firebox M370 | All versions |
| Watchguard | Firebox M390 | All versions |
| Watchguard | Firebox M440 | All versions |
| Watchguard | Firebox M4600 | All versions |
| Watchguard | Firebox M470 | All versions |
| Watchguard | Firebox M4800 | All versions |
| Watchguard | Firebox M5600 | All versions |
| Watchguard | Firebox M570 | All versions |
| Watchguard | Firebox M5800 | All versions |
| Watchguard | Firebox M590 | All versions |
| Watchguard | Firebox M670 | All versions |
| Watchguard | Firebox M690 | All versions |
| Watchguard | Firebox Nv5 | All versions |
| Watchguard | Firebox T20 | All versions |
| Watchguard | Firebox T25 | All versions |
| Watchguard | Firebox T40 | All versions |
| Watchguard | Firebox T45 | All versions |
Related Weaknesses (CWE)
References
- https://psirt.watchguard.com/CVE-2025-9242Broken Link
- https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2025-00015Vendor Advisory
- https://github.com/watchtowrlabs/watchTowr-vs-WatchGuard-CVE-2025-9242/blob/mainExploit
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-US Government Resource
FAQ
What is CVE-2025-9242?
CVE-2025-9242 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user V...
How severe is CVE-2025-9242?
CVE-2025-9242 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-9242?
Check the references section above for vendor advisories and patch information. Affected products include: Watchguard Fireware, Watchguard Firebox M270, Watchguard Firebox M290, Watchguard Firebox M370, Watchguard Firebox M390.