WatchGuard VPN Vulnerability Let Remote Attacker Execute Arbitrary Code
WatchGuard has identified a critical out-of-bounds write vulnerability in its Fireware OS, which permits remote, unauthenticated attackers to execute arbitrary code via IKEv2 VPN connections. This issue is designated as CVE-2025-9242 under advisory…
WatchGuard has identified a critical out-of-bounds write vulnerability in its Fireware OS, which permits remote, unauthenticated attackers to execute arbitrary code via IKEv2 VPN connections. This issue is designated as CVE-2025-9242 under advisory WGSA-2025-00015 and carries a CVSS 4.0 score of 9.3, indicating a high potential for exploitation on Firebox appliances.
The vulnerability, published on September 17, 2025, affects versions 11.10.2 to 11.12.4_Update1, 12.0 to 12.11.3, and 2025.1, posing risks such as full system compromise to small and midsize enterprises.
WatchGuard has urged organizations to apply patches immediately to mitigate threats from malicious actors targeting perimeter defenses.
The vulnerability is located in the IKE process of Fireware OS, which manages IKEv2 negotiations for mobile users and branch office VPNs configured with dynamic gateway peers. It can be triggered by sending crafted IKE_SA_INIT and IKE_SA_AUTH packets, causing an out-of-bounds write due to insufficient bounds checking in the ike2_ProcessPayload_CERT function.
WatchGuard has urged organizations to apply patches immediately to mitigate threats from malicious actors targeting perimeter defenses.
Even deleted VPN configurations may pose residual vulnerabilities if static peers remain active, enabling pre-authentication access over UDP port 500. Security researchers at WatchTowr Labs identified a simple length check addition as the fix after reverse-engineering the code through patch diffing.
WatchGuard has released updated versions to address the issue: 2025.1.1 for the 2025 branch, 12.11.4 for 12.x, 12.5.13 for T15/T35 models, and 12.3.1_Update3 for FIPS-certified 12.3.1. The 11.x versions are now end-of-life.
Affected products include Firebox families such as T20 to M690 series, Cloud, and NV5/V models. Organizations are advised to secure IPSec/IKEv2 branch office VPNs according to WatchGuard's knowledge base article on access controls and disable unnecessary IKEv2 if feasible.
No in-the-wild exploits have been confirmed, but the detailed public analysis increases the urgency for patching. Users should monitor logs for unusual IKE traffic and apply patches promptly to protect VPN concentrators, which serve as critical gateways.
Based on reporting by Cyber Security News.
