S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Oct 23, 2025

CVE-2025-9242 Scanner

CVE-2025-9242 Scanner - WatchGuard Fireware OS Remote Code Execution (RCE) Scanner

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.1k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2025-9242
9.3
CVSScritical
Exploitable remotely over the internet · no authentication required.

An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer. If the Firebox was previously configured with the mobile user VPN with IKEv2 or a branch office VPN using IKEv2 to a dynamic gateway peer, and both of those configurations have since been deleted, that Firebox may still be vulnerable if a branch office VPN to a static gateway peer is still configured.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Fireware OSby WatchGuard
11.0
Fireware OSby WatchGuard
AFFECTED< 12.3.1+722811SAFE ✓≥ 12.3.1+722811
Fireware OSby WatchGuard
AFFECTED< 12.5.13SAFE ✓≥ 12.5.13
Updated Aug 22, 2026View on NVD →
Detail

WatchGuard Fireware OS is a network operating system widely used in network security devices such as firewalls and VPNs. It provides features like intrusion prevention, VPN gateways, and malware protection suitable for enterprise-level security. Administered by IT professionals, it aims to secure networks from unauthorized access and cyber threats. Regular updates and patches are crucial to maintaining its security and functionality. Organizations across different industries, including healthcare and finance, rely on it to protect sensitive data. Its robustness and scalability make it a preferred choice for network protection in complex environments.

The Remote Code Execution (RCE) vulnerability allows attackers to execute arbitrary code on a vulnerable system, leading to potential full system compromise. This vulnerability arises from improper handling when using IKEv2 dynamic gateway peer within the VPN configurations. An RCE vulnerability poses significant risks, allowing unauthorized remote attackers to gain control over the affected system. This vulnerability can be especially dangerous as it can be exploited without authentication. Addressing such vulnerabilities promptly is critical to preventing malicious attacks and maintaining system integrity.

The vulnerability specifically targets the IKEv2 protocol implementation in the affected versions of WatchGuard Fireware OS. An out-of-bounds write occurs due to improper handling, which can be triggered by remote, unauthenticated attackers. Exploiting this vulnerability requires sending specially crafted packets to the VPN service with IKEv2. The vulnerable endpoint is the VPN interface configured for dynamic gateway peer connections. Successful exploitation allows attackers to execute arbitrary code, potentially leading to full control over the device.

If this vulnerability is exploited, malicious actors could execute arbitrary code, compromising the entire system's security. This could lead to unauthorized data access, data loss, or system downtime. Additionally, the attacker might install backdoors or malware, further endangering network security. The organization's reputation and compliance status could also be at risk due to exposure to such vulnerabilities. Therefore, timely patching and regular security assessments are essential to prevent potential exploits.

REFERENCES

Solution Advice
  • Ensure that all WatchGuard Fireware OS devices are updated to the latest version beyond 2025.1.
  • Regularly review and update firewall rules and VPN configurations to align with best security practices.
  • Conduct regular security audits and penetration tests to identify and mitigate potential vulnerabilities.
  • Implement additional security layers such as intrusion prevention systems (IPS) and application layer firewalls to monitor and block suspicious traffic.
  • Ensure that only authorized personnel have access to the administration interfaces of network security devices.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.