{"id":"CVE-2025-9242","title":"An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code","summary":"An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office V…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-787"],"vendor":"watchguard","product":"fireware","affected":["fireware >= 11.10.2, < 12.11.4","fireware >= 11.10.2, < 12.5.13","fireware = 2025.1"],"patched":["fireware 12.5.13"],"published":"2025-09-17","updated":"2026-08-10","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-9242","references":[{"url":"https://psirt.watchguard.com/CVE-2025-9242","label":"5d1c2695-1a31-4499-88ae-e847036fd7e3"},{"url":"https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2025-00015","label":"5d1c2695-1a31-4499-88ae-e847036fd7e3"},{"url":"https://github.com/watchtowrlabs/watchTowr-vs-WatchGuard-CVE-2025-9242/blob/main/watchTowr-vs-WatchGuard-CVE-2025-9242.py","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-9242","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","kev","in-the-wild","exploit-available"],"epss":0.913,"epssPercentile":0.99806,"kev":true,"kevDateAdded":"2025-11-12","kevDueDate":"2025-12-03","kevRansomware":false,"exploited":true,"ingestedAt":"2026-08-11T16:47:03.726Z","exploits":{"github":2,"githubRepos":["https://github.com/watchtowrlabs/watchTowr-vs-WatchGuard-CVE-2025-9242","https://github.com/UnusualGiraffe/WatchGuard-CVE-2025-9242-PoC-and-Mass-Scanner"],"checkedAt":"2026-09-23T07:13:38.597Z"},"exploitAvailable":true,"slug":"CVE-2025-9242","body":"## Overview\n\nAn Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer.\nIf the Firebox was previously configured with the mobile user VPN with IKEv2 or a branch office VPN using IKEv2 to a dynamic gateway peer, and both of those configurations have since been deleted, that Firebox may still be vulnerable if a branch office VPN to a static gateway peer is still configured.\n\n## Affected\n\n- `fireware >= 11.10.2, < 12.11.4`\n- `fireware >= 11.10.2, < 12.5.13`\n- `fireware = 2025.1`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `fireware 12.5.13`","depth":"hadal","depthScore":97,"depthScoreParts":{"impact":53.9,"likelihood":18.3,"exploitation":25,"ransomware":0},"changes":[{"seq":4875,"id":"CVE-2025-9242","ts":1788887212813,"field":"exploit_available","old":"false","new":"true"},{"seq":3758,"id":"CVE-2025-9242","ts":1788886329433,"field":"exploit_available","old":"true","new":"false"},{"seq":2603,"id":"CVE-2025-9242","ts":1788883010506,"field":"exploit_available","old":"false","new":"true"},{"seq":1632,"id":"CVE-2025-9242","ts":1788882410810,"field":"exploit_available","old":"true","new":"false"},{"seq":742,"id":"CVE-2025-9242","ts":1788881848024,"field":"exploit_available","old":"false","new":"true"}]}