CVE-2025-9242
An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer. If the Firebox was previously configured with the mobile user VPN with IKEv2 or a branch office VPN using IKEv2 to a dynamic gateway peer, and both of those configurations have since been deleted, that Firebox may still be vulnerable if a branch office VPN to a static gateway peer is still configured.
- Affected products
- Watchguard Fireware
- Watchguard Fireware
- < 12.11.4
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 91.3% (100th percentile)
- Weakness
- CWE-787
- NVD status
- Analyzed
- Published
- 2025-09-17
Fix
Fireware OS 2025.1.1, Fireware OS 12.11.4, Fireware OS 12.5.13, Fireware OS 12.3.1+722811
Workaround
If your Firebox is only configured with Branch Office VPN tunnels to static gateway peers and you are not able to immediately upgrade the device to a version of Fireware OS with the vulnerability resolution, you can follow WatchGuard’s recommendations for Secure Access to Branch Office VPNs that Use IPSec and IKEv2 as a temporary workaround.
5 known exploits for CVE-2025-9242
Proof-of-concept code and exploit modules indexed by Sploitus