CVE-2025-9242CRITICAL 9.8CISA KEVEPSS p99.7%

CVE-2025-9242WatchGuard Firebox Out-of-Bounds Write Vulnerability

WatchGuard / Firebox

Description

WatchGuard Firebox contains an out-of-bounds write vulnerability in the OS iked process that may allow a remote unauthenticated attacker to execute arbitrary code.

Scoring

CVSS 3.19.8 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS86.37% probability of exploitation · percentile 99.7% · 2026-06-15T12:03:41Z
Published2025-09-17
Last modified2025-11-14

CISA KEV entry

Added to KEV: 2025-11-12

Underlying weaknesses· 1

CWE-787

References

  1. https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2025-00015
  2. https://github.com/watchtowrlabs/watchTowr-vs-WatchGuard-CVE-2025-9242/blob/main/watchTowr-vs-WatchGuard-CVE-2025-9242.py
  3. https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-9242

1

TypeTargetConfidenceTier
WeaknessOut-of-bounds Writecwe-7870%live

(incoming)1

TypeTargetConfidenceTier
KEVEntryWatchGuard Firebox Out-of-Bounds Write Vulnerabilitykev-cve-2025-92420%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
WatchGuard Firebox Out of Bounds Write Vulnerability
CVE
WatchGuard Firebox and XTM Appliances Arbitrary Code Execution
CVE
WatchGuard Firebox and XTM Privilege Escalation Vulnerability
CVE
Fortinet FortiOS Out-of-Bound Write Vulnerability
CVE
CVE-2025-53844
CVE
CVE-2025-62550
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.