Critical Remote Code Execution Flaw Exposes Thousands of WatchGuard Firebox Firewalls to Immediate Attack

# WatchGuard Releases Critical Security Update for Firebox Firewalls

WatchGuard has issued urgent security patches to fix a critical remote code execution vulnerability affecting its Firebox firewall systems. The flaw, designated CVE-2025-9242, poses a significant threat to network security infrastructure worldwide.

## The Vulnerability Details

The security weakness stems from an out-of-bounds write error in the Fireware OS iked process. This critical flaw allows remote attackers to execute malicious code on vulnerable devices without authentication, potentially giving them complete control over affected firewalls.

**Affected Systems:**
– Fireware OS 11.x (end of life)
– Fireware OS 12.x
– Fireware OS 2025.1

The vulnerability specifically impacts firewalls configured with IKEv2 VPN services, including both mobile user VPNs and branch office VPNs using dynamic gateway peers.

## Fixed Versions and Affected Models

WatchGuard has released patches in the following versions:
– 12.3.1_Update3 (B722811)
– 12.5.13
– 12.11.4
– 2025.1.1

The vulnerability affects numerous firewall models across different product lines, including T-series, M-series, Firebox Cloud, and FireboxV systems.

## Important Configuration Warning

Even if administrators have removed vulnerable IKEv2 configurations, their systems may still be at risk. WatchGuard warns that firewalls previously configured with mobile user VPN or branch office VPN using IKEv2 to dynamic gateway peers remain vulnerable if any branch office VPN to static gateway peers is still active.

## Immediate Action Required

While the vulnerability is not currently being exploited in the wild, security experts strongly recommend immediate patching. For organizations unable to update immediately, WatchGuard provides a temporary workaround involving:
– Disabling dynamic peer BOVPNs
– Adding new firewall policies
– Disabling default system policies handling VPN traffic

## Why This Matters

Firewalls represent prime targets for cybercriminals seeking network access. Recent examples include the Akira ransomware group actively exploiting SonicWall vulnerabilities, and CISA’s 2022 directive requiring federal agencies to patch exploited WatchGuard flaws.

With WatchGuard protecting over 250,000 small and mid-sized companies globally through 17,000+ security partners, this vulnerability could impact a significant portion of the cybersecurity infrastructure.

## Conclusion

Organizations using WatchGuard Firebox systems should prioritize applying these security updates immediately. The combination of remote code execution capability and the critical nature of firewall infrastructure makes this vulnerability a high-priority security concern that requires swift remediation.

Share This Article