CVE-2025-9242

Published Sep 17, 2025

Last updated 4 months ago

Exploit knownCVSS critical 9.3
WatchGuard Fireware OS

Overview

Description
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the Mobile User VPN with IKEv2 and the Branch Office VPN using IKEv2 when configured with a dynamic gateway peer.This vulnerability affects Fireware OS 11.10.2 up to and including 11.12.4_Update1, 12.0 up to and including 12.11.3 and 2025.1.
Source
5d1c2695-1a31-4499-88ae-e847036fd7e3
NVD status
Analyzed
Products
fireware

Risk scores

CVSS 4.0

Type
Secondary
Base score
9.3
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
CRITICAL

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
WatchGuard Firebox Out-of-Bounds Write Vulnerability
Exploit added on
Nov 12, 2025
Exploit action due
Dec 3, 2025
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weaknesses

5d1c2695-1a31-4499-88ae-e847036fd7e3
CWE-787

Social media

Hype score
Not currently trending
  1. Critical WatchGuard Fireware OS Flaw Enables Remote Code Execution A critical out-of-bounds write flaw (CVE-2025-9242) in WatchGuard Fireware OS could allow remote code executionA critical out-of-bounds write flaw (CVE-2025-9242) in WatchGuard Fireware OS could allow remote c...

    @SecurityAid

    9 Mar 2026

    77 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. اکانت‌های به‌اصطلاح سایبری دارن VPN و تونلینگ رو تبلیغ می‌کنن، درحالی‌که VPN اگه پچ و درست کانفیگ نشه می‌تونه از اینترنت محدود هم خطرناک‌تر باشه؛ چون تون

    @DNSecAnon

    20 Jan 2026

    567 Impressions

    2 Retweets

    2 Likes

    0 Bookmarks

    1 Reply

    1 Quote

  3. WatchGuard Fireware OS IKEv2 Out-of-Bounds Write CVE-2025-9242 https://t.co/bwe1odJ2Py

    @crawopeucefau

    5 Jan 2026

    38 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. ''yIKEs (WatchGuard Fireware OS IKEv2 Out-of-Bounds Write CVE-2025-9242)'' #infosec #pentest #redteam #blueteam https://t.co/YkqCQ49cgA

    @CyberWarship

    4 Jan 2026

    1887 Impressions

    2 Retweets

    21 Likes

    5 Bookmarks

    0 Replies

    0 Quotes

  5. WatchGuard Fireware OS IKEv2 Out-of-Bounds Write (CVE-2025-9242) https://t.co/EpqqZiu0R2 Credits @_mccaulay #infosec https://t.co/Tha9AEbTTe

    @0xor0ne

    29 Dec 2025

    7245 Impressions

    10 Retweets

    107 Likes

    35 Bookmarks

    0 Replies

    0 Quotes

  6. csirt_it: ‼️ #WatchGuard: sfruttamento in rete della CVE-2025-9242, vulnerabilità “critica” che interessa i firewall #Firebox Rischio: 🔴 Tipologia: 🔸 Remote Code Execution 🔗 https://t.co/hH2Mvs1kvz 🔄Aggiornamenti disponibili🔄 https://t.co/NnPLMwxJoR

    @Vulcanux_

    19 Dec 2025

    40 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. ‼️ #WatchGuard: sfruttamento in rete della CVE-2025-9242, vulnerabilità “critica” che interessa i firewall #Firebox Rischio: 🔴 Tipologia: 🔸 Remote Code Execution 🔗 https://t.co/c5YZcvr2bc 🔄Aggiornamenti disponibili🔄 https://t.co/8KGZWFssGJ

    @csirt_it

    19 Dec 2025

    50 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. pre-auth RCE (CVE-2025-9242) stack buffer overflow vulnerability in WatchGuard Fireware OS https://t.co/8gUrO3steS Credits @watchtowrcyber #infosec https://t.co/v4ft0JravA

    @0xor0ne

    5 Dec 2025

    7042 Impressions

    20 Retweets

    153 Likes

    62 Bookmarks

    3 Replies

    0 Quotes

  9. yIKEs (WatchGuard Fireware OS IKEv2 Out-of-Bounds Write CVE-2025-9242) by @_mccaulay https://t.co/oViXnmPczV https://t.co/epSSdFjjdm

    @alexjplaskett

    3 Dec 2025

    3963 Impressions

    6 Retweets

    47 Likes

    21 Bookmarks

    1 Reply

    0 Quotes

  10. 🚨 WatchGuard Firebox admins: Zero-day alert! CVE-2025-9242 (out-of-bounds write in iked) lets remote attackers run arbitrary code—no auth needed. Quick fix: Patch per WatchGuard's advisory (wgsa-2025-00015). Monitor for unusual traffic. Unpatched firewalls = easy entry poi

    @AsensoDerrick3

    28 Nov 2025

    43 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. KEV ALERT: WatchGuard Firebox (CVE-2025-9242) and Gladinet Triofox (CVE-2025-12480) flaws are actively exploited for network access. Patch now. More info in: https://t.co/uE1zEpfVl8 https://t.co/EF1IQrPCbd

    @58Consulting

    21 Nov 2025

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. CISA warns of CVE-2025-9242, a critical RCE flaw in WatchGuard Fireware 12.x that lets attackers take over firewalls. 🔗 https://t.co/JqYDSYXl6Q MAD Security offers 24/7 SOC, MDR, and vuln support. #MADSecurity #CyberDefense

    @MADSecurityLLC

    21 Nov 2025

    15 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. 🚨 #CISA says hackers are exploiting a serious #WatchGuard firewall flaw (CVE-2025-9242, score 9.3). Attackers can run code without logging in. Over 54,000 Firebox devices are still exposed. Patch before Dec 3. Details ↓ https://t.co/Ms9fIRShbC Via @TheHackersNews

    @upgradeoptions

    21 Nov 2025

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. 🔒🚨 CISA adds critical security flaw affecting WatchGuard Fireware CVE-2025-9242 (CVSS 9.3) 🔥 Stay vigilant! #CyberSecurity #Exploitation #Fireware #ProtectYourNetwork 🔗Source: https://t.co/lXOplyhWbu

    @JamaalChalid

    17 Nov 2025

    20 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. 🚨 WatchGuard Fireware CVE-2025-9242 Critical Vulnerability Advisory [Critical] Nov 17, 2025 Checkout our Threat Intelligence Platform: https://t.co/QuwNtEgYh1 https://t.co/QuwNtEgYh1 #ThreatIntelligence #CyberSecurity #Innovation #LLM https://t.co/I3nugyhUDJ

    @transilienceai

    17 Nov 2025

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. 🚨 CISA varuje před kritickou chybou CVE-2025-9242 ve Firebox firewallech. Zranitelnost byla přidána do KEV a spočívá v out-of-bounds write ve Firebox OS. Podle agentury je zranitelnost aktivně zneužívána a je doporučeno provést aktualizaci co nejdříve. #ITbezpec

    @AlefSecurity

    14 Nov 2025

    37 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  17. CISA Flags Critical WatchGuard Fireware Flaw Exposing 54,000 Fireboxes to No-Login Attacks (CVE-2025-9242) https://t.co/lFpp1ngyPI #patchmanagement

    @eyalestrin

    13 Nov 2025

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. CVE-2025-9242 is a critical WatchGuard Firebox flaw that lets attackers hit VPN firewalls without a login and users need to patch fast. https://t.co/mMrbptiokY #CVE20259242 #Firebox #Cybersecurity https://t.co/iwUCHZsnun

    @JeniSystems

    13 Nov 2025

    46 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. 🚨#buyingcontent    #monkeyapp      #telegramlink #buysnaphack CISA says hackers are exploiting a serious WatchGuard firewall flaw (CVE-2025-9242, score 9.3). Attackers can run code without logging in. Over 54,000 Firebox devices are still exposed. Patch before D

    @silentwolf12347

    13 Nov 2025

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. 🚨 CVE-2025-9242 CVSS 9.3 🔥 Active Exploitation Confirmed! CVE-2025-9242 is an out-of-bounds write vulnerability in WatchGuard Firebox iked process. It scores 9.3 CVSS and enables remote unauthenticated arbitrary code execution. CISA added it to Known Exploited Vulnerabilit

    @cytexsmb

    13 Nov 2025

    148 Impressions

    2 Retweets

    4 Likes

    3 Bookmarks

    2 Replies

    2 Quotes

  21. 📢 CISA KEV UPDATE: Three vulnerabilities are now under active attack, including flaws in WatchGuard Firebox (CVE-2025-9242) and Gladinet Triofox (CVE-2025-12480). Federal agencies must patch by Dec 3. All orgs urged to act now! #CISA #KEV #CyberSec... 🔗 https://t.co/W8Kn6s

    @NetSecIO

    13 Nov 2025

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. WatchGuard Firebox CVE-2025-9242 (CVSS 9.3) enables unauthenticated RCE; actively exploited - patch now and review logs. https://t.co/erUNTLtz7L #infosec #CVE2025-9242 #WatchGuard

    @_UncleHacker_

    13 Nov 2025

    12 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. "APT 'GoldenJackal' Exploits WatchGuard Firebox Out-of-Bounds Flaw CISA added CVE-2025-9242, a critical out-of-bounds write flaw in WatchGuard Firebox firewalls, to its KEV list, warning of active exploitation. The vulnerability poses severe risks to organizations relying on htt

    @Secwiserapp

    13 Nov 2025

    34 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  24. Critical WatchGuard Firebox Vulnerability Exploited in Attacks. Tracked as CVE-2025-9242 (CVSS score of 9.3), the flaw leads to unauthenticated, remote code execution on vulnerable firewalls. https://t.co/uG9dtv0sD2 https://t.co/w4YXKuL6yL

    @riskigy

    13 Nov 2025

    38 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  25. 🚨 CISA flags a critical flaw in WatchGuard Fireware (CVE-2025-9242) ➡️ Exploited in the wild ➡️ 54K+ Fireboxes exposed ➡️ Allows unauthenticated code execution https://t.co/pXlMShFSso #CyberSecurity #CISA #WatchGuard #CVE20259242 #InfoSec #Vulert

    @vulert_official

    13 Nov 2025

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  26. 🔥 𝐂𝐈𝐒𝐀 𝐰𝐚𝐫𝐧𝐬 𝐨𝐟 𝐖𝐚𝐭𝐜𝐡𝐆𝐮𝐚𝐫𝐝 𝐟𝐢𝐫𝐞𝐰𝐚𝐥𝐥 𝐟𝐥𝐚𝐰 𝐞𝐱𝐩𝐥𝐨𝐢𝐭𝐞𝐝 𝐢𝐧 𝐚𝐭𝐭𝐚𝐜𝐤𝐬 • CVE-2025-9242 allows remote attackers to execute code on

    @PurpleOps_io

    13 Nov 2025

    32 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  27. 👀 Critical hole CVE-2025-9242 in WatchGuard Fireware opens over 54,000 Firebox-devices for attacks without any login. 📍 A bug in IKE-handshake allows you to sneak into iked even before checking the certificate and executing arbitrary code is the dream of any attacker 😈 h

    @Hack_Your_Mom

    13 Nov 2025

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  28. CISA alerts of an actively exploited out-of-bounds write flaw (CVE-2025-9242) in WatchGuard Firebox firewalls across versions 11.x to 2025.1. Over 54,000 devices remain vulnerable worldwide, mainly in Europe and North America. #Firewalls #USA https://t.co/GjvU2YeHlX

    @TweetThreatNews

    13 Nov 2025

    82 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  29. CISA just slapped a deadline on a live WatchGuard firewall zero-day (CVE-2025-9242). If your perimeter is your “strategy,” you’re already behind. Patch fast, assume breach, and push AI-driven detection to the edge. This is your wake-up call. #Cybersecurity #AI https://t.co/

    @LavxNews

    13 Nov 2025

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  30. 🚨 CRITICAL WatchGuard Fireware flaw (CVE-2025-9242) exposes 54,000+ Fireboxes to no-login remote code execution! Patch now to protect your network. Key targets: US, Italy, UK, Germany. Details: https://t.co/SylGWmESQY... https://t.co/GpskwVjV2P

    @offseq

    13 Nov 2025

    40 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  31. CISA, WatchGuard Fireware OS 11.10.2'de kritik CVE-2025-9242 zafiyetini (CVSS 9.3) tespit etti. Bu bellek dışı yazma hatası, 54.000 Firebox cihazını aktif olarak istismar edilen giriş yapmama saldırılarına karşı savunmasız bırakıyor. https://t.co/3PdFkaYZG5

    @err_cod

    13 Nov 2025

    246 Impressions

    1 Retweet

    5 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  32. CISA adds critical WatchGuard Fireware flaw (CVE-2025-9242) to KEV. Exploited, 54K+ Fireboxes at risk of no-login attacks. Update ASAP! 🚨 https://t.co/3xKoHgz47A #WatchGuard #CISA #CVE20259242 #CyberSecurity

    @0xT3chn0m4nc3r

    13 Nov 2025

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  33. 📌 أضافت وكالة الأمن السيبراني الأمريكية (CISA) ثغرة حرجة في برنامج WatchGuard Fireware إلى قائمة الثغرات المعروفة. الثغرة، CVE-2025-9242، تؤثر على نظام Fireware OS 11.10.2 ولا تتط

    @Cybercachear

    13 Nov 2025

    63 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  34. 🇺🇸 🚨 BREAKING: CISA adds CVE-2025-9242 (CVSS 9.3) affecting WatchGuard Fireware OS 11.10.2 to the KEV catalog after evidence of active exploitation. Patch or apply mitigations immediately. https://t.co/nptjfsRrRE #CyberSecurity #CVE #WatchGuard

    @STRATINT_AI

    13 Nov 2025

    17 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  35. 🚨 CISA says hackers are exploiting a serious WatchGuard firewall flaw (CVE-2025-9242, score 9.3). Attackers can run code without logging in. Over 54,000 Firebox devices are still exposed. Patch before Dec 3. Details ↓ https://t.co/mUvnNWSANZ

    @TheHackersNews

    13 Nov 2025

    28936 Impressions

    85 Retweets

    249 Likes

    36 Bookmarks

    3 Replies

    6 Quotes

  36. 米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログに以下を追加。 - WatchGuard FireboxのCVE-2025-9242 - Gladinet TriofoxのCVE-2025-12480 - WindowsのCVE-2025-62215 対処期限は何れも通常の12/3

    @__kokumoto

    12 Nov 2025

    1877 Impressions

    0 Retweets

    3 Likes

    5 Bookmarks

    1 Reply

    1 Quote

  37. ⚠️CISA has today added WatchGuard CVE-2025-9242 (OOB Write Vulnerability) to their Known Exploited Vulnerabilities list 👉We have added WatchGuard as a new feed option for Defused TF subscribers Go get those IOCs! 🍯🍯🍯 https://t.co/OlsM2OuifF

    @DefusedCyber

    12 Nov 2025

    5052 Impressions

    7 Retweets

    13 Likes

    11 Bookmarks

    1 Reply

    1 Quote

  38. 統合版 JPCERT/CC | Weekly Report: WatchGuard製ファイアウォール「Firebox」のikedにおける境界外書込みの脆弱性(CVE-2025-9242)について https://t.co/1tQhHRbEjM #itsec_jp

    @itsec_jp

    31 Oct 2025

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  39. WatchGuard VPN の脆弱性 CVE-2025-9242 が FIX:RCE の可能性と PoC の提供 https://t.co/B8lRaeDyTw WatchGuard Firebox の脆弱性は、IKEv2 の識別データを固定長スタックバッファへコピーする際の長さ検証不足によるスタックバッフ

    @iototsecnews

    27 Oct 2025

    27 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  40. 一般社団法人JPCERT コーディネーションセンター(JPCERT/CC)は10月21日、WatchGuard製ファイアウォール「Firebox」のVPN接続を処理するサービスikedにおける境界外書込みの脆弱性(CVE-2025-9242)について発表した。影

    @DieZeitDrangte

    23 Oct 2025

    57 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  41. 🚨 CVE-2025-9242 - critical 🚨 WatchGuard IKEv2 Out-of-Bounds Write Vulnerability > WatchGuard Fireware OS 11.10.2 to 11.12.4_Update1, 12.0 to 12.11.3, and 2025.1 contai... 👾 https://t.co/HqDdX8X5xC @pdnuclei #NucleiTemplates #cve

    @pdnuclei_bot

    23 Oct 2025

    23 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  42. 2025.10.21 CyberNewsFlash WatchGuard製ファイアウォール「Firebox」のikedにおける境界外書込みの脆弱性(CVE-2025-9242)について - 一般社団法人 JPCERT コーディネーションセンター(JPCERT/CC) https://t.co/Rhg069fXtl

    @kawn2020

    22 Oct 2025

    51 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  43. WatchGuard Fireboxの脆弱性CVE-2025-9242による影響と対策 https://t.co/wRxxBFDMp0 #Security #セキュリティー #ニュース

    @SecureShield_

    22 Oct 2025

    34 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  44. WatchGuard製ファイアウォール「Firebox」のikedにおける境界外書込みの脆弱性(CVE-2025-9242)について #JPCERTCC (Oct 21) https://t.co/AXwj7rIzvb

    @foxbook

    21 Oct 2025

    413 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  45. امن سازی آسیب پذیری مربوط به Firebox appliance با کد شناسایی CVE-2025-9242 https://t.co/02kgKMncnl https://t.co/Bfd8mYB6j8

    @EthicalSafe

    21 Oct 2025

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  46. 👀 Over 75 thousand WatchGuard Firebox devices in the world remain vulnerable to critical error CVE-2025-9242, which allows code execution without authentication. Despite the release of the patch, most systems in 🇺🇸, 🇩🇪, 🇮🇹 and 🇬🇧 still not updated. Vuln

    @Hack_Your_Mom

    21 Oct 2025

    20 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  47. 🔴WatchGuard Firewall RCE: 71,000+ Devices at Risk 🔴 Over 71,000 internet-exposed WatchGuard firewalls running vulnerable IKEv2 code (CVE-2025-9242). Out-of-bounds write in packet processing allows unauthenticated RCE. Attackers gain full device control and pivot to interna

    @the_c_protocol

    21 Oct 2025

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  48. CyberNewsFlash「WatchGuard製ファイアウォール「Firebox」のikedにおける境界外書込みの脆弱性(CVE-2025-9242)について」を公開。実証コードの公開により今後本脆弱性を悪用した攻撃の増加が懸念されます。開発者が

    @jpcert

    21 Oct 2025

    2606 Impressions

    4 Retweets

    6 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  49. 統合版 JPCERT/CC | お知らせ:CyberNewsFlash「WatchGuard製ファイアウォール「Firebox」のikedにおける境界外書込みの脆弱性(CVE-2025-9242)について」 https://t.co/TXKyJRiGay #itsec_jp

    @itsec_jp

    21 Oct 2025

    19 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  50. Over 75,000 WatchGuard security devices vulnerable to critical RCE (CVE-2025-9242) https://t.co/zowuCFqxXf #patchmanagement

    @eyalestrin

    21 Oct 2025

    29 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations