← Vulnerability feed

Vulnerability record · CVE-2025-9242 · published 17 September 2025

CVE-2025-9242: WatchGuard Fireware OS iked out-of-bounds write

Watchguard · Fireware

WatchGuard Fireware OS contains an out-of-bounds write in the iked process that can let a remote, unauthenticated attacker execute arbitrary code. It affects mobile user VPN with IKEv2 and branch office VPN using IKEv2 with a dynamic gateway peer, and a Firebox may remain exposed even after those configurations are deleted if a static-gateway branch office VPN is still configured. Because the flaw is reachable over the network with no credentials, it is a serious perimeter risk for internet-facing Fireboxes.

9.3 CVSS 4.0 Critical CISA KEV since 12 Nov 2025 EPSS 91% · top 0.2% CWE-787 · Out-of-bounds write
9.3CVSS 4.0 base score
91%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
4References, 1 tagged exploit
10 Aug 2026Last modified by NVD

Description

An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer. If the Firebox was previously configured with the mobile user VPN with IKEv2 or a branch office VPN using IKEv2 to a dynamic gateway peer, and both of those configurations have since been deleted, that Firebox may still be vulnerable if a branch office VPN to a static gateway peer is still configured.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityRemote unauthenticated code execution on internet-facing VPN appliances, listed in CISA KEV with a public exploit and very high EPSS probability.

What it is

WatchGuard Fireware OS contains an out-of-bounds write in the iked process that can let a remote, unauthenticated attacker execute arbitrary code. It affects mobile user VPN with IKEv2 and branch office VPN using IKEv2 with a dynamic gateway peer, and a Firebox may remain exposed even after those configurations are deleted if a static-gateway branch office VPN is still configured. Because the flaw is reachable over the network with no credentials, it is a serious perimeter risk for internet-facing Fireboxes.

Impact

A successful attacker can execute arbitrary code on the Firebox, potentially gaining full control of the device and the network traffic and tunnels it terminates. That can expose or disrupt the VPN-protected networks behind it.

Attack surface

The flaw is reached over the network through the iked process handling IKEv2, with no authentication or user interaction required per the CVSS vector (AV:N/PR:N/UI:N). Any Firebox running an affected configuration with IKEv2 exposed is a candidate target.

Exploitation

CVE-2025-9242 is listed in CISA KEV (added 2025-11-12) and has a public proof-of-concept exploit reference, and EPSS gives it a 0.913 30-day probability (99.8th percentile), indicating active exploitation is expected. No ransomware campaign use is documented in the record.

What to do

  • Apply the WatchGuard Fireware OS update referenced in advisory WGSA-2025-00015 as soon as possible.
  • If patching is not immediately possible, disable or restrict IKEv2 mobile user VPN and dynamic-gateway branch office VPN configurations, and review Fireboxes that previously had those configurations deleted but still run a static-gateway branch office VPN.
  • Limit IKEv2 exposure to trusted source addresses where operationally feasible, and follow CISA BOD 22-01 guidance or discontinue use if mitigations are unavailable.
  • Monitor WatchGuard advisories and CISA KEV for updated guidance and due dates (KEV remediation due 2025-12-03).

Detection

  • Review Firebox configuration and logs for IKEv2 mobile user VPN or dynamic-gateway branch office VPN settings, including deleted configurations, to identify exposed devices.
  • Monitor iked process crashes, restarts or abnormal behavior on Fireboxes, which may indicate exploitation attempts.
  • Hunt for unexpected outbound connections, new accounts or configuration changes on Firebox management interfaces following IKEv2 traffic.
  • Use the public proof-of-concept reference to build detection signatures for IKEv2 traffic patterns associated with the flaw.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-9242 to the Known Exploited Vulnerabilities catalog on 12 November 2025 as "WatchGuard Firebox Out-of-Bounds Write Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 3 December 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-9242 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-26318WatchGuard Fireware OS unauthenticated remote code executionWatchGuard Firebox and XTM appliances running Fireware OS contain an unauthenticated remote code execution flaw tracked as FBX-22786. An attacker who…KEVEPSS 78%analysed9.3CVE-2025-14733WatchGuard Fireware iked out-of-bounds write allows remote code executionWatchGuard Fireware OS contains an out-of-bounds write in the iked process reachable over the network. It affects IKEv2 mobile user VPN and branch of…KEVEPSS 27%analysed8.8CVE-2022-23176WatchGuard Fireware management access privilege escalationWatchGuard Firebox and XTM appliances running Fireware OS allow a remote attacker holding unprivileged credentials to obtain a privileged management …KEVEPSS 11%analysed9.8CVE-2022-31789Watchguard fireware integer overflow vulnerabilityAn integer overflow in WatchGuard Firebox and XTM appliances allows an unauthenticated remote attacker to trigger a buffer overflow and potentially e…EPSS 1.9%9.3CVE-2013-6021Watchguard fireware memory buffer overflow vulnerabilityBuffer overflow in WGagent in WatchGuard WSM and Fireware before 11.8 allows remote attackers to execute arbitrary code via a long sessionid value in…EPSS 12%9.2CVE-2026-13368Watchguard fireware use after free vulnerabilityWatchGuard Fireware OS contains a race condition leading to a use-after-free vulnerability in LDAP authentication for the Mobile User VPN with IKEv2.…EPSS 0.94%9.1CVE-2022-25361Watchguard fireware vulnerabilityWatchGuard Firebox and XTM appliances allow an unauthenticated remote attacker to delete arbitrary files from a limited set of directories on the sys…EPSS 1.3%8.8CVE-2022-25291Watchguard fireware integer overflow vulnerabilityAn integer overflow in WatchGuard Firebox and XTM appliances allows an authenticated remote attacker to trigger a heap-based buffer overflow and pote…EPSS 1.8%

Source: NIST National Vulnerability Database (record CVE-2025-9242), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.