logo

A Vulnerability in WatchGuard Fireware OS Could Allow for Arbitrary Code Execution

ID: a0d7ede2-a586-5b97-a9e5-c314ddebb69a

STIX ID: report--a0d7ede2-a586-5b97-a9e5-c314ddebb69a

Feed Name: CISecurity.org Advisories

Threat Score
70/100

Date Published: 2025-09-19

Date Updated: 2026-04-27

...
...

A remote unauthenticated out‑of‑bounds write vulnerability (CVE-2025-9242) in the WatchGuard Fireware OS iked process can allow arbitrary code execution against devices configured with IKEv2 mobile user or branch office VPNs, including cases where deleted VPN configurations persist; successful exploitation could enable full system compromise depending on user privileges. The advisory describes affected configurations and potential impacts but does not report active exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.