Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
perimeter-device-exposurewidely-deployed-product-advisoryembedded-device-vulnerabilityinternet-exposed-service

Critical Remote Code Execution Vulnerability in WatchGuard Fireware OS VPN

Updated 2d agoFirst seen Oct 21, 20253 sources

A critical vulnerability, tracked as CVE-2025-9242, has been discovered in WatchGuard's Fireware OS, affecting a wide range of Firebox network security appliances. This flaw is an out-of-bounds write in the 'iked' process, which is responsible for handling IKEv2 VPN negotiations. The vulnerability allows remote attackers to execute arbitrary code on affected devices without authentication, posing a severe risk to organizations relying on these appliances for network security. The issue specifically impacts devices configured with mobile user VPNs or branch office VPNs using IKEv2 with dynamic gateway peers. Security researchers have demonstrated that attackers can exploit this bug by sending specially crafted IKEv2 packets during the IKE_SA_AUTH phase, triggering a buffer overflow in the ike2_ProcessPayload_CERT function. Once exploited, attackers can gain control of the instruction pointer, establish Python interactive shells over TCP, and escalate to a full Linux shell by remounting filesystems and deploying BusyBox binaries. The vulnerability has been assigned a CVSS score of 9.3, underscoring its critical nature. According to scans by The Shadowserver Foundation, nearly 76,000 Firebox appliances remain exposed and vulnerable on the public internet, with the highest concentrations in the United States, Germany, Italy, the United Kingdom, Canada, and France. Affected Fireware OS versions include 11.10.2 through 11.12.4_Update1, the entire 12.0 series up to 12.11.3, and the 2025.1 release, impacting both older and newer Firebox models. WatchGuard has released patches in versions 12.3.1_Update3, 12.5.13, 12.11.4, and 2025.1.1 to address the vulnerability. Devices running version 11.x are no longer supported and will not receive security updates, prompting the vendor to recommend upgrading to a supported version. For appliances configured only with Branch Office VPNs to static gateway peers, WatchGuard has provided documentation for securing connections as a temporary workaround. The vulnerability transforms trusted security appliances into potential entry points for attackers, threatening the integrity of network defenses. Organizations are urged to assess their Firebox deployments, prioritize patching, and review VPN configurations to mitigate the risk. The widespread exposure of vulnerable devices highlights the urgency of remediation efforts. WatchGuard's disclosure and the subsequent public scanning have brought significant attention to the issue, emphasizing the importance of timely patch management in network security infrastructure. Failure to address this vulnerability could result in unauthorized access, lateral movement, and compromise of sensitive internal networks. The incident serves as a stark reminder of the risks posed by critical flaws in security appliances and the need for continuous monitoring and rapid response.

Share:
Critical Remote Code Execution Vulnerability in WatchGuard Fireware OS VPN
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Oct 21, 20258mo ago

More than 75,000 vulnerable Firebox appliances remain exposed a month later

On October 21, 2025, reporting indicated that over 75,000 internet-exposed WatchGuard Firebox devices were still vulnerable more than a month after patches became available. The affected systems were especially concentrated in the U.S., Germany, Italy, the U.K., Canada, and France, underscoring slow patch adoption.

Oct 20, 20258mo ago

Shadowserver finds nearly 76,000 internet-exposed vulnerable Firebox devices

By October 20, 2025, Shadowserver Foundation scans showed that almost 76,000 WatchGuard Firebox appliances remained exposed on the public internet and vulnerable to CVE-2025-9242. Reports said the largest concentrations were in the United States and Europe and noted no active exploitation had been reported at that time.

Sep 17, 202510mo ago

WatchGuard discloses CVE-2025-9242 and releases patches

On September 17, 2025, WatchGuard disclosed the critical Firebox vulnerability CVE-2025-9242, an out-of-bounds write in the Fireware OS 'iked' process that can enable unauthenticated remote code execution via crafted IKEv2 packets. The company released patched Fireware versions, advised temporary workarounds for some VPN configurations, and said unsupported 11.x devices must be upgraded because they will not receive fixes.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

4 LINKEDOpen in app
Organizations
3 linked
WatchGuard TechnologiesBleepingComputerShadowServer Foundation
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.