Junglewise Threat Intelligence

CVE-2025-9242: WatchGuard Fireware OS out-of-bounds write in iked process

CVE-2025-9242 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2025-11-12

Technologies: Watchguard XTM, Watchguard Firebox, Watchguard Fireware OS, Watchguard XTM Appliances. Vendors: Watchguard.

Executive brief

WatchGuard Firebox appliances, which are used to secure corporate networks and provide encrypted VPN access, contain a critical security flaw. An attacker can exploit this vulnerability over the internet without any login credentials to take complete control of the device. This could lead to a total network compromise, data theft, or a complete shutdown of secure remote access services. This vulnerability is reportedly being exploited in the wild.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in the 'iked' process of WatchGuard Fireware OS. The flaw is triggered during the handling of IKEv2 packets and specifically affects configurations involving Mobile User VPN with IKEv2 or Branch Office VPN using IKEv2 with a dynamic gateway peer. A remote, unauthenticated attacker can exploit this by sending specially crafted packets to the VPN endpoint, leading to arbitrary code execution with high privileges. The vulnerability has been observed in active exploitation, and administrators should apply vendor-provided patches immediately.

Affected products

  • WatchGuard Fireware OS 11.10.2 through 11.12.4_Update1, 12.0 through 12.11.3, and 2025.1
  • WatchGuard Firebox Multiple models including M, T, NV, and Cloud/V series

Timeline

  • 2025-09-17: disclosed: Initial CVE entry created by WatchGuard
  • 2025-11-12: advisory: Vendor advisory and NVD publication
  • 2025-11-12: kev added: Added to CISA Known Exploited Vulnerabilities catalog
  • 2025-11-12: exploited: Confirmed active exploitation in the wild

Related threats