CVE-2025-9242: WatchGuard Firebox Out-of-Bounds Write Vulnerability
An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer. If the Firebox was previously configured with the mobile user VPN with IKEv2 or a branch office VPN using IKEv2 to a dynamic gateway peer, and both of those configurations have since been deleted, that Firebox may still be vulnerable if a branch office VPN to a static gateway peer is still configured.
Other sources
WatchGuard Firebox contains an out-of-bounds write vulnerability in the OS iked process that may allow a remote unauthenticated attacker to execute arbitrary code.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WatchGuard Fireware OSto a version that resolves this vulnerability.Fixed in 2025.1.1 - Upgrade
Upgrade
WatchGuard Fireware OSto a version that resolves this vulnerability.Fixed in 12.11.4 - Upgrade
Upgrade
WatchGuard Fireware OSto a version that resolves this vulnerability.Fixed in 12.5.13 - Upgrade
Upgrade
WatchGuard Fireware OSto a version that resolves this vulnerability.Fixed in 12.3.1+722811 - Configuration
Ensure the branch office VPN using IKEv2 is not configured to use a dynamic gateway peer; the device may remain vulnerable if mobile user VPN with IKEv2 and branch office VPN (both deleted) were previously configured and a branch office VPN to a static gateway peer is still configured.
WatchGuard Firebox VPN (IKEv2) gateway peer type = static gateway peer only - Compensating control
If mitigations are unavailable, discontinue use of the WatchGuard Firebox product; otherwise apply mitigations per vendor instructions and follow applicable BOD 22-01 guidance for cloud services.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9242?
CVE-2025-9242 is rated as a critical severity vulnerability due to its potential for allowing remote code execution.
How do I fix CVE-2025-9242?
To fix CVE-2025-9242, update WatchGuard Fireware OS to a version beyond 11.12.4_Update1 or 12.11.3.
What impact does CVE-2025-9242 have on affected systems?
CVE-2025-9242 may lead to unauthorized remote code execution on vulnerable systems.
Which versions of WatchGuard Fireware OS are affected by CVE-2025-9242?
CVE-2025-9242 affects WatchGuard Fireware OS versions from 11.10.2 to 11.12.4_Update1 and versions from 12.0 to 12.11.3.
Who can exploit CVE-2025-9242?
CVE-2025-9242 can be exploited by remote unauthenticated attackers targeting the VPN configurations on affected Fireware OS systems.