CVE Feed

    Dashboard / CVE / CVE-2025-9242

    CVE-2025-9242

    An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer. If the Firebox was previously configured with the mobile user VPN with IKEv2 or a branch office VPN using IKEv2 to a dynamic gateway peer, and both of those configurations have since been deleted, that Firebox may still be vulnerable if a branch office VPN to a static gateway peer is still configured.

    Published:Sep 17, 2025
    Last Modified:Aug 10, 2026
    EPS:Sep 17, 2025
    EPSS Score:0.91121
    CVSS Score:9.8

    CISA Notification

    Description

    An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer. If the Firebox was previously configured with the mobile user VPN with IKEv2 or a branch office VPN using IKEv2 to a dynamic gateway peer, and both of those configurations have since been deleted, that Firebox may still be vulnerable if a branch office VPN to a static gateway peer is still configured.

    Required Action:

    Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

    Notes:

    No extra notes provided.

    Due Date
    Dec 3, 2025
    282 days ago
    Alert Date
    Nov 12, 2025
    303 days ago

    Affected Products

    Vendor
    Watchguard
    Product
    Firebox M270
    Vendor
    Watchguard
    Product
    Firebox M290
    Vendor
    Watchguard
    Product
    Firebox M370
    Vendor
    Watchguard
    Product
    Firebox M390
    Vendor
    Watchguard
    Product
    Firebox M440
    Vendor
    Watchguard
    Product
    Firebox M4600
    Vendor
    Watchguard
    Product
    Firebox M470
    Vendor
    Watchguard
    Product
    Firebox M4800
    Vendor
    Watchguard
    Product
    Firebox M5600
    Vendor
    Watchguard
    Product
    Firebox M570
    Vendor
    Watchguard
    Product
    Firebox M5800
    Vendor
    Watchguard
    Product
    Firebox M590
    Vendor
    Watchguard
    Product
    Firebox M670
    Vendor
    Watchguard
    Product
    Firebox M690
    Vendor
    Watchguard
    Product
    Firebox Nv5
    Vendor
    Watchguard
    Product
    Firebox T115-w
    Vendor
    Watchguard
    Product
    Firebox T125
    Vendor
    Watchguard
    Product
    Firebox T125-w
    Vendor
    Watchguard
    Product
    Firebox T145
    Vendor
    Watchguard
    Product
    Firebox T145-w
    Vendor
    Watchguard
    Product
    Firebox T15
    Vendor
    Watchguard
    Product
    Firebox T185
    Vendor
    Watchguard
    Product
    Firebox T20
    Vendor
    Watchguard
    Product
    Firebox T25
    Vendor
    Watchguard
    Product
    Firebox T35
    Vendor
    Watchguard
    Product
    Firebox T40
    Vendor
    Watchguard
    Product
    Firebox T45
    Vendor
    Watchguard
    Product
    Firebox T55
    Vendor
    Watchguard
    Product
    Firebox T70
    Vendor
    Watchguard
    Product
    Firebox T80
    Vendor
    Watchguard
    Product
    Firebox T85
    Vendor
    Watchguard
    Product
    Fireboxcloud
    Vendor
    Watchguard
    Product
    Fireboxv
    Vendor
    Watchguard
    Product
    Fireware
    Vendor
    Watchguard
    Product
    Fireware Os

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High