WatchGuard warns of critical vulnerability in Firebox firewalls

A remote code execution issue affecting WatchGuard’s Firebox firewalls has been fixed with security updates.

This major security problem, identified as CVE-2025-9242, is caused by an out-of-bounds write vulnerability that, if successfully exploited, can enable attackers to remotely execute malicious code on susceptible devices.

Versions 12.3.1_Update3 (B722811), 12.5.13, 12.11.4, and 2025.1.1 all addressed CVE-2025-9242, which impacts firewalls running Fireware OS 11.x (end of life), 12.x, and 2025.1.

WatchGuard stated that although Firebox firewalls are only susceptible to attacks if they are set up to use IKEv2 VPN, they could still be compromised if a branch office VPN to a static gateway peer is still set up, even after the vulnerable configurations have been removed.

An Out-of-bounds An unauthorized remote attacker could be able to run arbitrary code due to a write vulnerability read more about WatchGuard warns of critical vulnerability in Firebox firewalls.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *