Critical WatchGuard Fireware OS Flaw Enables Remote Code Execution
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-9242 | Out-of-Bounds Write in WatchGuard Fireware OS iked Enables Unauthenticated RCE WatchGuard Fireware OS contains an out-of-bounds write (CWE-787) in the iked process that a remote, unauthenticated attacker can trigger to execute arbitrary code on the appliance. The flaw is reachable via the mobile user VPN with IKEv2 and via branch office VPNs using IKEv2 to a dynamic gateway peer; devices whose IKEv2 configurations were deleted may remain vulnerable if a branch office VPN to a static gateway peer is still configured. Successful exploitation yields full system compromise, reflected in the CVSS v4.0 base score of 9.3 (network vector, no privileges or user interaction, high impact on confidentiality, integrity and availability). WatchGuard Firebox appliances with IKEv2 VPN services are affected, with public reporting citing roughly 54,000 internet-exposed Fireboxes; the issue was added to CISA's Known Exploited Vulnerabilities catalog on 2025-11-12, a public proof-of-concept exploit exists, and headlines indicate use in ransomware attacks (KEV ransomware field is listed as unknown). EPSS assigns a 91.3% probability of exploitation within 30 days (100th percentile), so remediation urgency is high. Do: Apply the patched Fireware OS release per WatchGuard's security advisory immediately (exact fixed version numbers are not provided in the source data); the KEV listing makes BOD 22-01 remediation timelines mandatory for U.S. federal agencies. As an interim mitigation, restrict or disable IKEv2 VPN exposure — mobile user VPN with IKEv2 and branch office VPN IKEv2, including residual static-peer BOVPN configurations on devices that previously had IKEv2 configured — to trusted sources only. Administrators should audit configuration history to identify Fireboxes with prior IKEv2 mobile VPN or dynamic-peer BOVPN setups, since these may remain vulnerable even after the configs were deleted. | 9.3 | 91% | KEV PoC |
| large≈54,000 internet-exposed Fireboxes (public scan figure cited in coverage) |
Full article272 words · extracted from infosecurity-magazine.com · click to collapse
A critical vulnerability (CVSS4.0 9.3) in WatchGuard Fireware OS has been identified that could allow a threat actor to remotely execute arbitrary code.
The bug, tracked as CVE-2025-9242, is an out-of-bounds write vulnerability affecting mobile user VPN with IKEv2 and the branch office VPN (BOVPN) using IKEv2 when configured with a dynamic gateway peer.
The WatchGuard advisory noted that if the Firebox security platform was previously configured with the above VPN and IKEv2 gateway peers it could still be vulnerable.
The vulnerability affects Fireware OS 11.10.2 up to and including 11.12.4_Update1, 12.0 up to and including 12.11.3 and 2025.1.
WatchGuard’s Firebox is a next-generation firewall (NGFW) that acts as a security gateway, controlling traffic between external and trusted networks, and includes advanced features like intrusion prevention, anti-spam and content filtering.
It can be deployed as a physical appliance, in the cloud or as a virtual machine.
The Shadowserver foundation noted that based on IP data scans, there could be over 71,000 vulnerable devices as of October 17.
Details on the vulnerability are now available on the US National Vulnerability Database (NVD) and WatchGuard has also published a security advisory.
If the Firebox is only configured with Branch Office VPN tunnels to static gateway peers and the owner is not able to immediately upgrade the device to a version of Fireware OS with the vulnerability resolution, WatchGuard has provided recommendations for a temporary workaround.
In its advisory, WatchGuard noted that it recommends BOVPN secure access policies are configured with a narrower scope to handle incoming VPN traffic, due to increasing attacks against exposed VPNs that target a wide range of vendors.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/watchguard-fireware-os-flaw/