An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the Mobile User VPN with IKEv2 and the Branch Office VPN using IKEv2 when configured with a dynamic gateway peer.This vulnerability affects Fireware OS 11.10.2 up to and including 11.12.4_Update1, 12.0 up to and including 12.11.3 and 2025.1.
Metrics
Affected Vendors & Products
References
History
Thu, 18 Sep 2025 12:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Watchguard
Watchguard fireware |
|
Vendors & Products |
Watchguard
Watchguard fireware |
Wed, 17 Sep 2025 13:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 17 Sep 2025 08:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | WatchGuard Firebox IKEv2 VPN Pre-Authentication Remote Code Execution | WatchGuard Firebox iked Out of Bounds Write Vulnerability |
Wed, 17 Sep 2025 07:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the Mobile User VPN with IKEv2 and the Branch Office VPN using IKEv2 when configured with a dynamic gateway peer.This vulnerability affects Fireware OS 11.10.2 up to and including 11.12.4_Update1, 12.0 up to and including 12.11.3 and 2025.1. | |
Title | WatchGuard Firebox IKEv2 VPN Pre-Authentication Remote Code Execution | |
Weaknesses | CWE-787 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: WatchGuard
Published: 2025-09-17T07:29:23.738Z
Updated: 2025-09-18T03:55:13.473Z
Reserved: 2025-08-20T11:08:20.724Z
Link: CVE-2025-9242

Updated: 2025-09-17T12:57:15.519Z

Status : Awaiting Analysis
Published: 2025-09-17T08:15:33.960
Modified: 2025-09-17T14:18:55.093
Link: CVE-2025-9242

No data.