Vulnerability Details CVE-2025-9242
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the Mobile User VPN with IKEv2 and the Branch Office VPN using IKEv2 when configured with a dynamic gateway peer.This vulnerability affects Fireware OS 11.10.2 up to and including 11.12.4_Update1, 12.0 up to and including 12.11.3 and 2025.1.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.603
EPSS Ranking 98.2%
CVSS Severity
CVSS v3 Score 9.8
Proposed Action
WatchGuard Firebox contains an out-of-bounds write vulnerability in the OS iked process that may allow a remote unauthenticated attacker to execute arbitrary code.
Ransomware Campaign
Unknown
Products affected by CVE-2025-9242
-
cpe:2.3:h:watchguard:firebox_m270:-
-
cpe:2.3:h:watchguard:firebox_m290:-
-
cpe:2.3:h:watchguard:firebox_m370:-
-
cpe:2.3:h:watchguard:firebox_m390:-
-
cpe:2.3:h:watchguard:firebox_m440:-
-
cpe:2.3:h:watchguard:firebox_m4600:*
-
cpe:2.3:h:watchguard:firebox_m470:-
-
cpe:2.3:h:watchguard:firebox_m4800:-
-
cpe:2.3:h:watchguard:firebox_m5600:*
-
cpe:2.3:h:watchguard:firebox_m570:-
-
cpe:2.3:h:watchguard:firebox_m5800:-
-
cpe:2.3:h:watchguard:firebox_m590:-
-
cpe:2.3:h:watchguard:firebox_m670:-
-
cpe:2.3:h:watchguard:firebox_m690:-
-
cpe:2.3:h:watchguard:firebox_nv5:*
-
cpe:2.3:h:watchguard:firebox_t115-w:*
-
cpe:2.3:h:watchguard:firebox_t125-w:*
-
cpe:2.3:h:watchguard:firebox_t125:*
-
cpe:2.3:h:watchguard:firebox_t145-w:*
-
cpe:2.3:h:watchguard:firebox_t145:*
-
cpe:2.3:h:watchguard:firebox_t15:-
-
cpe:2.3:h:watchguard:firebox_t185:*
-
cpe:2.3:h:watchguard:firebox_t20:-
-
cpe:2.3:h:watchguard:firebox_t25:*
-
cpe:2.3:h:watchguard:firebox_t35:-
-
cpe:2.3:h:watchguard:firebox_t40:-
-
cpe:2.3:h:watchguard:firebox_t45:*
-
cpe:2.3:h:watchguard:firebox_t55:-
-
cpe:2.3:h:watchguard:firebox_t70:-
-
cpe:2.3:h:watchguard:firebox_t80:-
-
cpe:2.3:h:watchguard:firebox_t85:*
-
cpe:2.3:h:watchguard:fireboxcloud:-
-
cpe:2.3:h:watchguard:fireboxv:-
-
cpe:2.3:o:watchguard:fireware:11.11
-
cpe:2.3:o:watchguard:fireware:11.12.4
-
cpe:2.3:o:watchguard:fireware:12.0.0
-
cpe:2.3:o:watchguard:fireware:12.1.3
-
cpe:2.3:o:watchguard:fireware:12.1.4
-
cpe:2.3:o:watchguard:fireware:12.2.0
-
cpe:2.3:o:watchguard:fireware:12.5.10
-
cpe:2.3:o:watchguard:fireware:12.5.7
-
cpe:2.3:o:watchguard:fireware:12.5.9
-
cpe:2.3:o:watchguard:fireware:12.6.1
-
cpe:2.3:o:watchguard:fireware:12.6.3
-
cpe:2.3:o:watchguard:fireware:12.6.4
-
cpe:2.3:o:watchguard:fireware:12.7.0
-
cpe:2.3:o:watchguard:fireware:12.7.1
-
cpe:2.3:o:watchguard:fireware:12.7.2
-
cpe:2.3:o:watchguard:fireware:12.8.0
-
cpe:2.3:o:watchguard:fireware:2025.1