An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer.
If the Firebox was previously configured with the mobile user VPN with IKEv2 or a branch office VPN using IKEv2 to a dynamic gateway peer, and both of those configurations have since been deleted, that Firebox may still be vulnerable if a branch office VPN to a static gateway peer is still configured.
References
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
History
No history.
Information
Published : 2025-09-17 08:15
Updated : 2026-08-10 19:59
NVD link : CVE-2025-9242
Mitre link : CVE-2025-9242
CVE.ORG link : CVE-2025-9242
JSON object : View
Products Affected
watchguard
- firebox_t25
- firebox_t85
- firebox_nv5
- firebox_m495
- firebox_m4600
- firebox_m5800
- firebox_t80
- fireware
- firebox_t20
- fireboxcloud
- firebox_t70
- fireboxv
- firebox_m295
- firebox_m395
- firebox_m390
- firebox_m470
- firebox_m695
- firebox_m270
- firebox_m5600
- firebox_m590
- firebox_t145-w
- firebox_t15
- firebox_t185
- firebox_t35
- firebox_t55
- firebox_m595
- firebox_m440
- firebox_t45
- firebox_m670
- firebox_t125-w
- firebox_m370
- firebox_t115-w
- firebox_t145
- firebox_m570
- firebox_t125
- firebox_m690
- firebox_t40
- firebox_m4800
- firebox_m290
CWE
CWE-787
Out-of-bounds Write
