LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-9242: WatchGuard Firebox Out-of-Bounds Write Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 12, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Dec 3, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-9242 to its Known Exploited Vulnerabilities catalog on Nov 12, 2025, with a federal patch deadline of Dec 3, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

WatchGuard Firebox contains an out-of-bounds write vulnerability in the OS iked process that may allow a remote unauthenticated attacker to execute arbitrary code.

CVE-2025-9242 is an out-of-bounds write vulnerability in the OS iked process of WatchGuard Firebox appliances. A remote unauthenticated attacker may exploit it to execute arbitrary code. Because Firebox devices commonly sit at network perimeters as firewalls and VPN gateways, successful exploitation can give an attacker a foothold inside the protected environment and undermine the security controls the appliance is meant to enforce.

Defenders should treat this as a high-priority perimeter risk and confirm all details, including exact fixed versions and any configuration prerequisites, against the official WatchGuard advisory.

How it works

The weakness is classified as CWE-787 (out-of-bounds write). In this class of flaw, a process writes data past the end (or before the start) of an allocated buffer. When the write lands in adjacent memory that holds control data—such as function pointers, return addresses, or object metadata—an attacker who can influence the written content can redirect execution flow.

According to the CISA summary, the vulnerable component is the iked process that runs as part of the Firebox operating system. An unauthenticated remote attacker can reach this process over the network and trigger the out-of-bounds write, potentially achieving arbitrary code execution. Public detail on the precise packet format or trigger conditions is limited; teams must rely on the vendor advisory for any additional technical description rather than assuming specific exploit mechanics.

Am I affected? How to find it in your systems

WatchGuard Firebox appliances are typically deployed as hardware or virtual firewalls, often terminating IPsec or other VPN tunnels and enforcing network policy. Inventory every Firebox instance by:

Once located, compare the running software version and any relevant feature flags against the list of affected versions published in the vendor advisory. Because the flaw resides in the iked process, pay particular attention to devices that have IKE/IPsec services enabled or exposed to untrusted networks.

For detection of possible exploitation, examine logs and telemetry for anomalous traffic directed at IKE ports, unexpected process restarts of iked, or sudden configuration changes on the Firebox. Correlate these events with external connection attempts that do not match legitimate peer profiles. Confirm any recommended log signatures or indicators of compromise with the vendor advisory, as none are supplied in the public summary.

How to remediate

The primary remediation is to apply the vendor-supplied update that addresses CVE-2025-9242. Follow the installation and verification steps exactly as documented in the WatchGuard advisory. After patching, validate that the iked process is running the corrected code and that VPN and firewall services continue to operate as expected.

In addition to the patch, implement any configuration hardening or feature restrictions the vendor recommends for this vulnerability class. CISA’s required action further directs organizations to apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for any cloud-hosted instances, or discontinue use of the product if mitigations are unavailable. Document the remediation status of every Firebox for audit and compliance purposes.

If you can't patch immediately

Until the vendor update can be installed, reduce exposure with compensating controls:

These measures lower risk but do not eliminate it; schedule the official patch as soon as possible.

If your data may have been exposed

Actively exploited remote-code-execution vulnerabilities on perimeter devices frequently lead to broader network compromise and data exposure. Although ransomware use of this specific CVE is not documented, any successful intrusion should be treated as a potential breach. Review Firebox and downstream system logs for signs of unauthorized access, rotate credentials that may have traversed the appliance, and consider running a free exposure scan of organizational email addresses against known breach data sets to determine whether credentials or personal information have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedWatchGuard · Firebox
WeaknessCWE-787
Added to CISA KEVNov 12, 2025
Federal patch deadlineDec 3, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities