Vulnerability record · CVE-2025-9242 · published 17 September 2025
CVE-2025-9242: WatchGuard Fireware OS iked out-of-bounds write
Watchguard · Fireware
WatchGuard Fireware OS contains an out-of-bounds write in the iked process that can let a remote, unauthenticated attacker execute arbitrary code. It affects mobile user VPN with IKEv2 and branch office VPN using IKEv2 with a dynamic gateway peer, and a Firebox may remain exposed even after those configurations are deleted if a static-gateway branch office VPN is still configured. Because the flaw is reachable over the network with no credentials, it is a serious perimeter risk for internet-facing Fireboxes.
Description
An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer. If the Firebox was previously configured with the mobile user VPN with IKEv2 or a branch office VPN using IKEv2 to a dynamic gateway peer, and both of those configurations have since been deleted, that Firebox may still be vulnerable if a branch office VPN to a static gateway peer is still configured.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Automated analysis
critical priorityRemote unauthenticated code execution on internet-facing VPN appliances, listed in CISA KEV with a public exploit and very high EPSS probability.
What it is
WatchGuard Fireware OS contains an out-of-bounds write in the iked process that can let a remote, unauthenticated attacker execute arbitrary code. It affects mobile user VPN with IKEv2 and branch office VPN using IKEv2 with a dynamic gateway peer, and a Firebox may remain exposed even after those configurations are deleted if a static-gateway branch office VPN is still configured. Because the flaw is reachable over the network with no credentials, it is a serious perimeter risk for internet-facing Fireboxes.
Impact
A successful attacker can execute arbitrary code on the Firebox, potentially gaining full control of the device and the network traffic and tunnels it terminates. That can expose or disrupt the VPN-protected networks behind it.
Attack surface
The flaw is reached over the network through the iked process handling IKEv2, with no authentication or user interaction required per the CVSS vector (AV:N/PR:N/UI:N). Any Firebox running an affected configuration with IKEv2 exposed is a candidate target.
Exploitation
CVE-2025-9242 is listed in CISA KEV (added 2025-11-12) and has a public proof-of-concept exploit reference, and EPSS gives it a 0.913 30-day probability (99.8th percentile), indicating active exploitation is expected. No ransomware campaign use is documented in the record.
What to do
- Apply the WatchGuard Fireware OS update referenced in advisory WGSA-2025-00015 as soon as possible.
- If patching is not immediately possible, disable or restrict IKEv2 mobile user VPN and dynamic-gateway branch office VPN configurations, and review Fireboxes that previously had those configurations deleted but still run a static-gateway branch office VPN.
- Limit IKEv2 exposure to trusted source addresses where operationally feasible, and follow CISA BOD 22-01 guidance or discontinue use if mitigations are unavailable.
- Monitor WatchGuard advisories and CISA KEV for updated guidance and due dates (KEV remediation due 2025-12-03).
Detection
- Review Firebox configuration and logs for IKEv2 mobile user VPN or dynamic-gateway branch office VPN settings, including deleted configurations, to identify exposed devices.
- Monitor iked process crashes, restarts or abnormal behavior on Fireboxes, which may indicate exploitation attempts.
- Hunt for unexpected outbound connections, new accounts or configuration changes on Firebox management interfaces following IKEv2 traffic.
- Use the public proof-of-concept reference to build detection signatures for IKEv2 traffic patterns associated with the flaw.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-9242 to the Known Exploited Vulnerabilities catalog on 12 November 2025 as "WatchGuard Firebox Out-of-Bounds Write Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 3 December 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2025-9242 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-9242), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.