CISA Flags Critical WatchGuard Fireware Flaw Exposing 54,000 Fireboxes to No-Login Attacks
The United States On Wednesday, the Cybersecurity and Infrastructure Security Agency (CISA) included a critical security vulnerability affecting WatchGuard Fireware in its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
The vulnerability being referred to is CVE-2025-9242 (CVSS score: 9.3), which is an out-of-bounds write vulnerability that impacts Fireware OS versions 11.10.2 through 11.12.4_Update1, 12.0 through 12.11.3, and 2025.1.
CISA reported in an advisory that the OS iked process of WatchGuard Firebox has an out-of-bounds write vulnerability, which could enable a remote attacker without authentication to run arbitrary code.
Last month, watchTowr Labs disclosed specifics regarding the vulnerability, with the cybersecurity firm indicat...

