Over 71,000 WatchGuard Devices Exposed to Remote Code Execution Attacks
Recent reports have highlighted a significant security concern regarding WatchGuard devices, with over 71,000 units exposed to potential remote code execution attacks due to a vulnerability identified as CVE-2025-9242. This issue, discovered by security…
Recent reports have highlighted a significant security concern regarding WatchGuard devices, with over 71,000 units exposed to potential remote code execution attacks due to a vulnerability identified as CVE-2025-9242. This issue, discovered by security researchers, particularly affects the WatchGuard Fireware OS IKEv2 ISAKMP component, allowing unauthorized access through specially crafted network packets.
The vulnerability is an Out-of-Bounds Write in the IKEv2 ISAKMP component of WatchGuard Fireware OS. This flaw could enable remote attackers to execute arbitrary code on unpatched devices. The exposure is widespread, with over 71,000 devices identified globally, affecting a variety of sectors and geographies. The primary affected devices include firewall appliances and VPN gateways, which are critical in securing organizational remote access.
The scale of this vulnerability highlights the popularity of WatchGuard products and the potential attack surface for cybercriminals. Shadowserver has begun providing daily reports on compromised IPs linked to CVE-2025-9242, using active scanning to identify vulnerable systems. This initiative aims to assist organizations in taking immediate remediation actions.
The vulnerability is an Out-of-Bounds Write in the IKEv2 ISAKMP component of WatchGuard Fireware OS.
The daily reports indicate a significant delay in patching and remediation efforts by many organizations, despite public advisories. Unpatched WatchGuard devices face heightened risks of remote attacks, data theft, and potential business disruptions. Security experts strongly recommend that IT teams patch all affected systems and verify the absence of unauthorized access.
Implement immediate patching for all WatchGuard Fireware OS devices. Conduct thorough security audits to ensure no unauthorized access has occurred. Utilize threat intelligence platforms like Shadowserver for continuous monitoring and updates on exposed assets.
Maintaining vigilance and proactive security measures are essential in defending against vulnerabilities such as CVE-2025-9242.
Based on reporting by GBHackers.
