EXPOSURES › CVE-2025-9242
CVE-2025-9242
HIGH ⌖ ON CISA KEV · EXPLOITEDWatchGuard Firebox OS iked process allowed remote unauthenticated attackers to execute arbitrary code
A critical out-of-bounds write vulnerability in WatchGuard Firebox's OS iked process was actively exploited, enabling remote attackers to execute arbitrary code without authentication. This compromised the integrity and confidentiality of the systems it protected, posing a significant risk to DIB organizations.
Shame score — Critical remote code execution vulnerability actively exploited in the wild
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
WatchGuard Firebox contains an out-of-bounds write vulnerability in the OS iked process that may allow a remote unauthenticated attacker to execute arbitrary code.