CRITICAL🚩 CISA KEV⚡ EXPLOIT✓ PATCH🇵🇱 Wersja polska

CVE-2025-9242

CVSS 9.3v4.0pub. 2025-09-17upd. 2026-08-10

An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer. If the Firebox was previously configured with the mobile user VPN with IKEv2 or a branch office VPN using IKEv2 to a dynamic gateway peer, and both of those configurations have since been deleted, that Firebox may still be vulnerable if a branch office VPN to a static gateway peer is still configured.

🤖 AI Analysis
How it works

An out-of-bounds write error (CWE-787) occurs in IKEv2 protocol handling, which is used by both Mobile User VPN and Branch Office VPN configured with dynamic gateway peers. An attacker can send a specially crafted IKEv2 packet to the device without any authentication, leading to memory overwrite beyond the intended buffer. This results in the ability to hijack code execution flow in the Fireware operating system.

Impact

An attacker can remotely execute arbitrary code (RCE) with system privileges on a vulnerable WatchGuard Firebox device, leading to full compromise of the device, including control over network traffic passing through it.

Mitigation & patch

Apply patches available from the vendor according to the references (WatchGuard advisory WGSA-2025-00015 at watchguard.com/wgrd-psirt/advisory/wgsa-2025-00015). Due to active exploitation of the vulnerability in attacks and availability of public exploit code, the update should be deployed immediately. If immediate patching is not possible, consider disabling or restricting access to IKEv2 VPN functionality from external networks.

Who is affected

WatchGuard Firebox T70, M440, M370, M690, M470 running Fireware OS versions: 11.10.2 to 11.12.4_Update1 inclusive, 12.0 to 12.11.3 inclusive, and 2025.1

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Watchguard Fireboxcloud

    HW
    Watchguard
    all versions
  • Watchguard Firebox M270

    HW
    Watchguard
    all versions
  • Watchguard Firebox M290

    HW
    Watchguard
    all versions
  • Watchguard Firebox M295

    HW
    Watchguard
    all versions
  • Watchguard Firebox M370

    HW
    Watchguard
    all versions
  • Watchguard Firebox M390

    HW
    Watchguard
    all versions
  • Watchguard Firebox M395

    HW
    Watchguard
    all versions
  • Watchguard Firebox M440

    HW
    Watchguard
    all versions
  • Watchguard Firebox M4600

    HW
    Watchguard
    all versions
  • Watchguard Firebox M470

    HW
    Watchguard
    all versions
  • Watchguard Firebox M4800

    HW
    Watchguard
    all versions
  • Watchguard Firebox M495

    HW
    Watchguard
    all versions
  • Watchguard Firebox M5600

    HW
    Watchguard
    all versions
  • Watchguard Firebox M570

    HW
    Watchguard
    all versions
  • Watchguard Firebox M5800

    HW
    Watchguard
    all versions
  • Watchguard Firebox M590

    HW
    Watchguard
    all versions
  • Watchguard Firebox M595

    HW
    Watchguard
    all versions
  • Watchguard Firebox M670

    HW
    Watchguard
    all versions
  • Watchguard Firebox M690

    HW
    Watchguard
    all versions
  • Watchguard Firebox M695

    HW
    Watchguard
    all versions
  • Watchguard Firebox Nv5

    HW
    Watchguard
    all versions
  • Watchguard Firebox T115 W

    HW
    Watchguard
    all versions
  • Watchguard Firebox T125

    HW
    Watchguard
    all versions
  • Watchguard Firebox T125 W

    HW
    Watchguard
    all versions
  • Watchguard Firebox T145

    HW
    Watchguard
    all versions
  • Watchguard Firebox T145 W

    HW
    Watchguard
    all versions
  • Watchguard Firebox T15

    HW
    Watchguard
    all versions
  • Watchguard Firebox T185

    HW
    Watchguard
    all versions
  • Watchguard Firebox T20

    HW
    Watchguard
    all versions
  • Watchguard Firebox T25

    HW
    Watchguard
    all versions

CISA KEV — detailsi

Vendori
WatchGuard
Producti
Firebox
Added to KEVi
November 12, 2025
Remediation deadline (US Federal)i
December 3, 2025(overdue)
Required action (CISA)i

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CISA descriptioni

WatchGuard Firebox contains an out-of-bounds write vulnerability in the OS iked process that may allow a remote unauthenticated attacker to execute arbitrary code.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
CISA DEADLINE: 3 grudnia 2025
Tags
RCEAuth BypassMemoryVPN
CWE
References

Related vulnerabilities

CVE-2025-14733CRITICAL9.3⚠ KEVsame product

An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthentic...

CVE-2022-26318CRITICAL9.8⚠ KEVPL ✓same product

RCE bez uwierzytelnienia w WatchGuard Firebox i XTM (FBX-22786)

CVE-2026-13368CRITICAL9.2same product

WatchGuard Fireware OS contains a race condition leading to a use-after-free vulnerability in LDAP authenticat...

CVE-2022-31789CRITICAL9.8PL ✓same product

Integer overflow w WatchGuard Firebox/XTM umożliwiający RCE bez uwierzytelnienia

CVE-2022-25361CRITICAL9.1PL ✓same product

WatchGuard Firebox/XTM – zdalne usuwanie plików bez uwierzytelnienia