🔴 CVE-2025-9242

Critical out-of-bounds write vulnerability in WatchGuard Fireware OS affecting IKEv2 VPN services that allows unauthenticated remote code execution. This is actively exploited in the wild according to CISA KEV and affects security appliances that are inherently internet-facing by design.

← Back to Overview
HIGH_RISK
Risk Level
9.3
CVSS Score
NETWORK
Attack Vector
Initial Access
ATT&CK Tactic
T1190 — Exploit Public-Facing Application
ATT&CK Technique
VERY_HIGH
Deployment Risk
No
Ransomware

📋 Vulnerability Details

Data Source: CIRCL

Confidence: HIGH

Exploitation Method: DIRECT_NETWORK

CVE Published: 2025-09-17

Added to CISA KEV: 2025-11-12 56 DAYS BETWEEN CVE AND KEV

🎯 Recommendations:

🔍 Web Intelligence (Kagi · 2025-11-13)

CVE-2025-9242 is a critical out-of-bounds write vulnerability affecting WatchGuard Fireware OS, specifically the `iked` process responsible for IKEv2 VPN negotiations [1][8]. This vulnerability allows for unauthenticated remote code execution [11][10].

Here's a breakdown of what is known about its exploitation:

  • Internet-facing applications or services: Yes, CVE-2025-9242 affects internet-facing applications and services [4].
  • Active exploitation in the wild: CISA has added CVE-2025-9242 to its Known Exploited Vulnerabilities Catalog, indicating active exploitation [3][5].
  • Attack vectors and exploitation methods: The vulnerability can be exploited by sending specially crafted IKEv2 packets to vulnerable Firebox endpoints, forcing it to write data to unintended memory areas [1]. This can be done without authentication [6].
  • Targeted attacks: While not explicitly stated, the addition to CISA's KEV catalog and the potential for remote code execution suggests it could be used in targeted attacks [5][2].
  • CISA Known Exploited Vulnerabilities (KEV) status: CVE-2025-9242 is listed in CISA's KEV catalog [3][5].
  • Technical details about internet exploitability: The vulnerability is an out-of-bounds write in the Fireware OS `iked` process, which handles IKEv2 VPN negotiations [1]. It can be exploited without authentication by sending specially crafted IKEv2 packets to vulnerable Firebox endpoints [1][6]. This allows remote attackers to execute arbitrary code [11][12]. The CVSS score is 9.3, indicating critical severity [1][7].
The vulnerability affects Fireware OS versions 11.10.2 up to and including 11.12.4\_Update1, 12.0 up to and including 12.11.3, and 2025.1 [9][7].

Sources

  1. Over 75,000 WatchGuard security devices vulnerable to critical RCE

    WatchGuard disclosed CVE-2025-9242 in a security bulletin on September 17 and rated the vulnerability with a critical-severity score of 9.3. The security problem is an out-of-bounds write in the Fireware OS ‘iked’ process, which handles IKEv2 VPN negotiations. The flaw can be exploited without authe…

  2. Alert CISA Adds Three Known Exploited Vulnerabilities to Catalog...

    CVE-2025-9242.These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a livin…

  3. CISA Adds Three Known Exploited Vulnerabilities to Catalog

    CISA Adds Three Known Exploited Vulnerabilities to Catalog · CVE-2025-9242 WatchGuard Firebox Out-of-Bounds Write Vulnerability · CVE-2025-12480 ...

  4. Known Exploited Vulnerabilities Catalog

    CVE-2025-9242. WatchGuard Firebox Out-of-Bounds Write Vulnerability ... Successful exploitation of this vulnerability could enable the attacker to gain SYSTEM- ...

  5. Cleopatra’s Shadow: A Mass Exploitation Campaign... - Arctic Wolf

    September 17, 2025. CVE-2025-9242: Critical Unauthenticated Out-of-Bounds Write Vulnerability in WatchGuard Firebox.Additionally, devices should be continuously audited for potential weaknesses in internet-accessible services, and vulnerable services should be kept off the public internet where poss…