Tech Wavo
  • Home
  • Technology
  • Computers
  • Gadgets
  • Mobile
  • Apps
  • News
  • Financial
  • Stock
Tech Wavo
No Result
View All Result

WatchGuard warns users Firebox firewalls may have a critical issue – here’s what we know

Tech Wavo by Tech Wavo
September 20, 2025
in Computers
0




  • WatchGuard patched a critical VPN vulnerability allowing remote code execution on Firebox firewalls
  • CVE-2025-9242 affects dynamic gateway peer configurations, even after removal in some cases
  • No exploitation seen yet, but delayed patching leaves systems exposed to future targeted attacks

WatchGuard has fixed a critical-severity vulnerability affecting its Firebox firewalls and is urging users to apply the newly released patch without hesitation.

In a security advisory, the company said it addressed an out-of-bounds write vulnerability in the WatchGuard Fireware OS iked process, which “may allow a remote unauthenticated attacker to execute arbitrary code”.

The vulnerability was said to affect both the mobile user VPN with IKEv2, and the branch office VPN using IKEv2, when configured with a dynamic gateway peer. Furthermore, if the Firebox was previously configured with the mobile user VPN with IKEv2 or a branch office VPN using IKEv2 to a dynamic gateway peer, and both configurations were subsequently removed, the Firebox may still be vulnerable “if a branch office VPN to a static gateway peer is still configured”.


You may like

Workaround

The vulnerability is now tracked as CVE-2025-9242, and was given a severity score of 9.2/10 (critical). It affects firewalls running Fireware OS 11.x (end of life), 12.x, and 2025.1. The first clean version is 12.3.1_Update3 (B722811), 12.5.13, 12.11.4, and 2025.1.1.

Those who are unable to apply the fix immediately can deploy a workaround that includes disabling dynamic peer BOVPNs, adding new firewall policies, and disabling the default system policies that handle VPN traffic.

So far, there has been no evidence of abuse in the wild.

However, many criminals only start hunting for vulnerabilities after a patch is released, knowing that organizations rarely patch on time and often keep their systems exposed for longer periods of time.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

For example, in early 2025, threat actors exploited a Fortinet FortiGate vulnerability, tracked as CVE-2022-42475, more than a year after its disclosure.

Despite available patches, many devices remained exposed, while attackers used symbolic links to maintain stealthy access, extract credentials, and configuration data.

Via BleepingComputer

You might also like

Previous Post

How to watch UCI Road World Championships 2025 free online

Next Post

White label app development: top benefits revealed

Next Post
Scale Faster With Less Cost

White label app development: top benefits revealed

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Masked, not erased: how broken redaction fuels AI data leaks

by Tech Wavo
September 20, 2025
0
Masked, not erased: how broken redaction fuels AI data leaks
Computers

Sensitive corporate data is not just slipping into chatbots. It is leaking long before it ever gets there.Last month, a...

Read more

White label app development: top benefits revealed

by Tech Wavo
September 20, 2025
0
Scale Faster With Less Cost
Apps

The chaos of starting from scratch gets reduced via white label app development. It’s about brand management, speed, and cost...

Read more

WatchGuard warns users Firebox firewalls may have a critical issue – here’s what we know

by Tech Wavo
September 20, 2025
0
This long-exposed SonicWall flaw is being used to infect organizations with Akira ransomware – so patch now
Computers

WatchGuard patched a critical VPN vulnerability allowing remote code execution on Firebox firewallsCVE-2025-9242 affects dynamic gateway peer configurations, even after...

Read more

How to watch UCI Road World Championships 2025 free online

by Tech Wavo
September 20, 2025
0
How to watch UCI Road World Championships 2025 free online
Computers

Watch UCI Road World Championships 2025 live streams to see the elite event head to Africa for the first time...

Read more

Site links

  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of use
  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of use

No Result
View All Result
  • Home
  • Technology
  • Computers
  • Gadgets
  • Mobile
  • Apps
  • News
  • Financial
  • Stock