Skip to content
COOEY

EXPOSURES › CVE-2025-9242

CVE-2025-9242

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-11-12 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2025-9242 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatched

WatchGuard Firebox OS iked process allowed remote unauthenticated attackers to execute arbitrary code

A critical out-of-bounds write vulnerability in WatchGuard Firebox's OS iked process was actively exploited, enabling remote attackers to execute arbitrary code without authentication. This compromised the integrity and confidentiality of the systems it protected, posing a significant risk to DIB organizations.

Shame score — Critical remote code execution vulnerability actively exploited in the wild

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

WatchGuard Firebox contains an out-of-bounds write vulnerability in the OS iked process that may allow a remote unauthenticated attacker to execute arbitrary code.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.