logo

Over 75,000 WatchGuard security devices vulnerable to critical RCE

ID: ed7fa38c-c4e9-575d-86cf-eb412567bb07

STIX ID: report--ed7fa38c-c4e9-575d-86cf-eb412567bb07

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-10-20

Date Updated: 2026-07-19

Author: Bill Toulas

...
...

WatchGuard disclosed CVE-2025-9242, a critical (CVSS 9.3) out-of-bounds write in the Fireware 'iked' process that can enable unauthenticated remote code execution via specially crafted IKEv2 packets; Shadowserver scans indicate ~75–76k vulnerable Firebox appliances exposed on the public internet (largest counts in the US, Germany, Italy, UK, Canada, France). The vendor published patch updates (2025.1.1, 12.11.4, 12.5.13, 12.3.1_Update3) and guidance; administrators are urged to upgrade immediately, and no active exploitation has yet been reported.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.