Over 75,000 WatchGuard security devices vulnerable to critical RCE
ID: ed7fa38c-c4e9-575d-86cf-eb412567bb07
STIX ID: report--ed7fa38c-c4e9-575d-86cf-eb412567bb07
Feed Name: Bleeping Computer
WatchGuard disclosed CVE-2025-9242, a critical (CVSS 9.3) out-of-bounds write in the Fireware 'iked' process that can enable unauthenticated remote code execution via specially crafted IKEv2 packets; Shadowserver scans indicate ~75–76k vulnerable Firebox appliances exposed on the public internet (largest counts in the US, Germany, Italy, UK, Canada, France). The vendor published patch updates (2025.1.1, 12.11.4, 12.5.13, 12.3.1_Update3) and guidance; administrators are urged to upgrade immediately, and no active exploitation has yet been reported.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
