PT-2025-38127 · Watchguard · Watchguard Fireware
Btaol
·
Published
2025-09-17
·
Updated
2025-11-26
·
CVE-2025-9242
CVSS v2.0
10
10
Critical
| Base vector | Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
WatchGuard Fireware OS versions 11.10.2 through 11.12.4 Update1
WatchGuard Fireware OS versions 12.0 through 12.11.3
WatchGuard Fireware OS version 2025.1
Description
An out-of-bounds write vulnerability exists in the WatchGuard Fireware OS
iked process, potentially allowing a remote, unauthenticated attacker to execute arbitrary code. This vulnerability affects both Mobile User VPN with IKEv2 and Branch Office VPN using IKEv2 when configured with a dynamic gateway peer. Reports indicate active exploitation of this issue, with over 75,000 devices potentially exposed worldwide, with a significant concentration in the United States, Italy, the United Kingdom, Germany, and Canada. The vulnerability allows attackers to execute code without authentication, posing a severe risk to network security. The iked process handles IKEv2 VPN connections. Exploitation involves sending specially crafted IKEv2 packets to vulnerable Firebox appliances, leading to an out-of-bounds write and enabling arbitrary code execution.Recommendations
WatchGuard Fireware OS versions 11.10.2 through 11.12.4 Update1: Upgrade to version 2025.1.1, 12.11.4, 12.5.13, or 12.3.1 Update3 (B722811).
WatchGuard Fireware OS versions 12.0 through 12.11.3: Upgrade to version 2025.1.1, 12.11.4, 12.5.13, or 12.3.1 Update3 (B722811).
WatchGuard Fireware OS version 2025.1: Upgrade to version 2025.1.1, 12.11.4, 12.5.13, or 12.3.1 Update3 (B722811).
Rotate all locally stored secrets on affected appliances.
Limit IKEv2 to trusted configurations.
Exploit
Fix
RCE
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
dbugs@ptsecurity.com
Weakness Enumeration
Related Identifiers
BDU:2025-11474
CVE-2025-9242
Affected Products
Watchguard Fireware
References · 138
- 🔥 https://github.com/watchtowrlabs/watchTowr-vs-WatchGuard-CVE-2025-9242/blob/main/watchTowr-vs-WatchGuard-CVE-2025-9242.py⭐ 8 🔗 4 · Exploit
- https://nvd.nist.gov/vuln/detail/CVE-2025-9242 · Security Note
- https://watchguard.com/wgrd-psirt/advisory/wgsa-2025-00015 · Security Note, Vendor Advisory
- https://bdu.fstec.ru/vul/2025-11474 · Security Note
- https://twitter.com/shah_sheikh/status/1979189546731344058 · Twitter Post
- https://t.me/cveNotify/138934 · Telegram Post
- https://twitter.com/IT_news_for_all/status/1988871993282773124 · Twitter Post
- https://twitter.com/TheHackersNews/status/1988870432460595525 · Twitter Post
- https://twitter.com/_r_netsec/status/1978766141117051130 · Twitter Post
- https://twitter.com/TweetThreatNews/status/1969037754315985141 · Twitter Post
- https://twitter.com/dailytechonx/status/1989403466502897692 · Twitter Post
- https://reddit.com/r/CVEWatch/comments/1owtk8p/top_10_trending_cves_14112025 · Reddit Post
- https://twitter.com/0xT3chn0m4nc3r/status/1988879743626678273 · Twitter Post
- https://twitter.com/upgradeoptions/status/1991187966350573959 · Twitter Post
- https://twitter.com/PSuiteNetwork/status/1981971562551972057 · Twitter Post