Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-9242

98
FAUCET Score

CVE-2025-9242 is an Out-of-bounds Write vulnerability in WatchGuard Fireware OS, specifically affecting versions 11.10.2 through 11.12.4_Update1, 12.0 through 12.11.3, and 2025.1. This critical flaw allows a remote, unauthenticated attacker to execute arbitrary code when Mobile User VPN with IKEv2 or Branch Office VPN using IKEv2 with a dynamic gateway peer is configured. The vulnerability carries a CVSS score of 9.8 (CRITICAL), indicating a severe risk due to its network-based attack vector, low complexity, and high impact on confidentiality, integrity, and availability. Its EPSS score of 0.616090000 and FAUCET Risk Score of 100/100 further emphasize its significant threat. CVE-2025-9242 is actively exploited in the wild, as confirmed by its presence in the KEV catalog and CISA mandates for patching. While no Metasploit or ExploitDB modules are publicly available, Nuclei templates exist, and the vulnerability has garnered substantial community discussion and media coverage, highlighting its widespread concern.

Impacted Technologies

VendorProductVersion(s)CPE
>= 11.10.2, < 12.11.4CPE matchmatch criteria
cpe:2.3:o:watchguard:fireware:*:*:*:*:*:*:*:*
>= 11.10.2, < 12.5.13CPE matchmatch criteria
cpe:2.3:o:watchguard:fireware:*:*:*:*:*:*:*:*
2025.1CPE matchmatch criteria
cpe:2.3:o:watchguard:fireware:2025.1:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

9.3CRITICAL

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
91.12%
Probability of exploitation in next 30 days
EPSS Percentile
99.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
Added to KEV · Nov 12, 2025
Nuclei: CVE-2025-9242 · Oct 16, 2025
This CVE's current EPSS score of 0.9112 is in the 99th percentile among its peer group of 36,835 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (7)

3cxvendor investigatingvia llm_extracted
amazonvendor investigatingvia llm_extracted
horillavendor investigatingvia llm_extracted
inveniosoftwarevendor investigatingvia llm_extracted
jitsivendor investigatingvia llm_extracted
leantimevendor investigatingvia llm_extracted
nutanixvendor investigatingvia llm_extracted

Vendor Advisories (7)

leantimellm-leantime-71544fc3538a5313CRITICAL

WatchGuard Fireware Out-of-Bounds Write (CVE-2025-9242)

Mar 19, 2026
amazonllm-amazon-74073f92d34502a1CRITICAL

WatchGuard Fireware Out-of-Bounds Write (CVE-2025-9242)

Mar 19, 2026
nutanixllm-nutanix-fa62b60d6bcb64c0CRITICAL

WatchGuard Fireware Out-of-Bounds Write (CVE-2025-9242)

Mar 19, 2026
horillallm-horilla-7edef72c071b3883CRITICAL

WatchGuard Fireware Out-of-Bounds Write (CVE-2025-9242)

Mar 19, 2026
inveniosoftwarellm-inveniosoftware-6b5d32c5cda97d65CRITICAL

WatchGuard Fireware Out-of-Bounds Write (CVE-2025-9242)

Mar 19, 2026
jitsillm-jitsi-9d2c7f4cc0d237a2CRITICAL

WatchGuard Fireware Out-of-Bounds Write (CVE-2025-9242)

Mar 19, 2026
3cxllm-3cx-04ccce58d4c0b245CRITICAL

WatchGuard Fireware Out-of-Bounds Write (CVE-2025-9242)

Mar 19, 2026

References

github.com / watchtowrlabs/watchTowr-vs-WatchGuard-CVE-2025-9242/blob/main/watchTowr-vs-WatchGuard-CVE-2025-9242.py
Exploit
cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
watchguard.com / wgrd-psirt/advisory/wgsa-2025-00015
Vendor Advisory