PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Network Vulnerabilities·Updated Oct 23, 2025

WatchGuard IKEv2 Out-of-Bounds Write Vulnerability

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.3k
Times Used
continuous scan runs
0
Continuously Checked
assets under CS
1
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2025-9242
9.3
CVSScritical
Exploitable remotely over the internet · no authentication required.

An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer. If the Firebox was previously configured with the mobile user VPN with IKEv2 or a branch office VPN using IKEv2 to a dynamic gateway peer, and both of those configurations have since been deleted, that Firebox may still be vulnerable if a branch office VPN to a static gateway peer is still configured.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Fireware OSby WatchGuard
11.0
Fireware OSby WatchGuard
AFFECTED< 12.3.1+722811SAFE ✓≥ 12.3.1+722811
Fireware OSby WatchGuard
AFFECTED< 12.5.13SAFE ✓≥ 12.5.13
Updated Sep 9, 2026View on NVD →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.