Answer in brief
CVE-2025-9242 records a High severity (CVSS 9.8) vulnerability in WatchGuard Firebox iked Out of Bounds Write Vulnerability. The current sources mark it as known exploited. The current feed maps WatchGuard/Fireware OS (generic), WatchGuard/Fireware OS (generic), WatchGuard/Fireware OS (generic), WatchGuard/Fireware OS (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 9.8. Known-exploitation status makes exposure review time-sensitive. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps WatchGuard/Fireware OS (generic), WatchGuard/Fireware OS (generic), WatchGuard/Fireware OS (generic), WatchGuard/Fireware OS (generic). Check affected ranges and fixed versions before updating.
| Product | Affected versions | Fixed versions |
|---|---|---|
| cpe:2.3:h:watchguard:fireboxcloud:*:*:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:h:watchguard:firebox_m270:*:*:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:h:watchguard:firebox_m290:*:*:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:h:watchguard:firebox_m295:-:*:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:h:watchguard:firebox_m370:*:*:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:h:watchguard:firebox_m390:*:*:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:h:watchguard:firebox_m395:-:*:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:h:watchguard:firebox_m440:*:*:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:h:watchguard:firebox_m4600:*:*:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:h:watchguard:firebox_m470:*:*:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:h:watchguard:firebox_m4800:*:*:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:h:watchguard:firebox_m495:-:*:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:h:watchguard:firebox_m5600:*:*:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:h:watchguard:firebox_m570:*:*:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:h:watchguard:firebox_m5800:*:*:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:h:watchguard:firebox_m590:*:*:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:h:watchguard:firebox_m595:-:*:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:h:watchguard:firebox_m670:*:*:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:h:watchguard:firebox_m690:*:*:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:h:watchguard:firebox_m695:-:*:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:h:watchguard:firebox_nv5:*:*:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:h:watchguard:firebox_t115-w:*:*:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:h:watchguard:firebox_t125:*:*:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:h:watchguard:firebox_t125-w:*:*:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:h:watchguard:firebox_t145:*:*:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:h:watchguard:firebox_t145-w:*:*:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:h:watchguard:firebox_t15:*:*:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:h:watchguard:firebox_t185:*:*:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:h:watchguard:firebox_t20:*:*:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:h:watchguard:firebox_t25:*:*:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:h:watchguard:firebox_t35:*:*:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:h:watchguard:firebox_t40:*:*:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:h:watchguard:firebox_t45:*:*:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:h:watchguard:firebox_t55:*:*:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:h:watchguard:firebox_t70:*:*:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:h:watchguard:firebox_t80:*:*:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:h:watchguard:firebox_t85:*:*:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:h:watchguard:fireboxv:*:*:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:o:watchguard:fireware:*:*:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:o:watchguard:fireware:2025.1:*:*:*:*:*:*:* | Not reported | Not reported |
| Package | Affected range | Fixed version |
|---|---|---|
| WatchGuard/Fireware OSgeneric | 12.0 || 11.10.2 || 2025.0 | Not reported |
| WatchGuard/Fireware OSgeneric | 11.0 || >=12.0 <12.11.4 || >=2025.0 <2025.1.1 | 12.11.4, 2025.1.1 |
| WatchGuard/Fireware OSgeneric | >=12.0 <12.3.1+722811 | 12.3.1+722811 |
| WatchGuard/Fireware OSgeneric | >=12.0 <12.5.13 | 12.5.13 |
Published upstream
Sep 17, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
May 24, 2026
Added to CISA KEV
Nov 12, 2025
Evidence: source:kev:kev:kev:recordAn Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer. If the Firebox was previously configured with the mobile user VPN with IKEv2 or a branch office VPN using IKEv2 to a dynamic gateway peer, and both of those configurations have since been deleted, that Firebox may still be vulnerable if a branch office VPN to a static gateway peer is still configured.
Quoted source text, attributed separately from HOL analysis.