PT-2025-38127 · Watchguard · Watchguard Fireware
Btaol
·
Published
2025-09-17
·
Updated
2026-01-05
·
CVE-2025-9242
CVSS v3.1
10
10
Critical
| Base vector | Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WatchGuard Fireware OS versions 11.10.2 through 11.12.4 Update1
WatchGuard Fireware OS versions 12.0 through 12.11.3
WatchGuard Fireware OS version 2025.1
Description
An out-of-bounds write vulnerability exists in WatchGuard Fireware OS, specifically within the iked process responsible for IKEv2 VPN connections. This flaw allows a remote, unauthenticated attacker to execute arbitrary code on affected Firebox devices. The vulnerability impacts both Mobile User VPN with IKEv2 and Branch Office VPN using IKEv2 when configured with a dynamic gateway peer. Reports indicate active exploitation of this vulnerability, with over 75,000 devices potentially exposed globally, with a significant concentration in the United States, Italy, the United Kingdom, and Germany. The vulnerability is tracked as CVE-2025-9242 and has a CVSS score of 9.3, indicating a critical severity. The vulnerability allows attackers to execute code without authentication, potentially granting them full control over VPN gateways and enabling lateral movement within internal networks.
Recommendations
WatchGuard Fireware OS versions 11.10.2 through 11.12.4 Update1: Upgrade to version 2025.1.1, 12.11.4, 12.5.13, or 12.3.1 Update3 (B722811).
WatchGuard Fireware OS versions 12.0 through 12.11.3: Upgrade to version 2025.1.1, 12.11.4, 12.5.13, or 12.3.1 Update3 (B722811).
WatchGuard Fireware OS version 2025.1: Upgrade to version 2025.1.1, 12.11.4, 12.5.13, or 12.3.1 Update3 (B722811).
Rotate all locally stored secrets on affected appliances.
Limit IKEv2 to trusted configurations.
Exploit
Fix
RCE
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
dbugs@ptsecurity.com
Weakness Enumeration
Related Identifiers
BDU:2025-11474
CVE-2025-9242
Affected Products
Watchguard Fireware
References · 153
- 🔥 https://github.com/watchtowrlabs/watchTowr-vs-WatchGuard-CVE-2025-9242/blob/main/watchTowr-vs-WatchGuard-CVE-2025-9242.py⭐ 8 🔗 4 · Exploit
- https://watchguard.com/wgrd-psirt/advisory/wgsa-2025-00015 · Security Note, Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-9242 · Security Note
- https://bdu.fstec.ru/vul/2025-11474 · Security Note
- https://twitter.com/andrewcheeky/status/1990553512414150703 · Twitter Post
- https://twitter.com/riskigy/status/1988983196189352330 · Twitter Post
- https://twitter.com/BarracudaMSP/status/1984032624118006055 · Twitter Post
- https://t.me/CSIRT_italia/3011 · Telegram Post
- https://t.me/pentestingnews/68407 · Telegram Post
- https://reddit.com/r/CVEWatch/comments/1oxozj7/top_10_trending_cves_15112025 · Reddit Post
- https://t.me/secharvester/20371 · Telegram Post
- https://twitter.com/Shadowserver/status/1979902019696509099 · Twitter Post
- https://t.me/CSIRT_italia/2818 · Telegram Post
- https://cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-9242 · Note
- https://twitter.com/not2cleverdotme/status/1980441261812138192 · Twitter Post