- watchguard
- fireware
- ikev2
- vpn
- cve
- rce
- appliance
news
WatchGuard Fireware IKEv2 Out-of-Bounds Write (CVE-2025-9242)
Critical Fireware IKEv2 flaw with version-pinned PoC and detection-only scanner resurfaced in Sploitus weekly list; triage internet-facing VPN endpoints.
Summary
CVE-2025-9242 is a critical out-of-bounds write in WatchGuard Fireware IKEv2 handling. In late July 2026, Sploitus featured authorized-use tooling that splits detection-only IKEv2 fingerprinting from a version-pinned exploit path (Fireware 12.7 build 640389 in the indexed repo). CVSS on the Sploitus card: 9.8.
The scanner sends ordinary non-overflowing IKE_SA_INIT probes and parses WatchGuard vendor version/build fields — triage without triggering the bug. The exploit component is gated and refuses non-matching builds. OFFSITE.DARK indexes the Sploitus listing for asset owners; we do not redistribute triggers.
Technical Details
| Aspect | Detail |
|---|---|
| CVE | CVE-2025-9242 |
| Product | WatchGuard Fireware (VPN / firewall appliances) |
| Vector | Network-facing IKEv2 |
| Class | Out-of-bounds write |
| Public tooling pattern | Separate scanner (no trigger) vs pinned PoC |
Defenders should treat internet-exposed IKE endpoints as high priority for version inventory regardless of whether a specific PoC build matches.
Impact
Remote compromise of VPN/firewall appliances — typically high-value footholds into enterprise networks. Historical WatchGuard IKEv2 bugs have driven mass scanning; assume opportunistic probing whenever tooling is public.
Mitigation
- Apply WatchGuard Fireware updates addressing CVE-2025-9242; confirm build numbers from vendor advisories.
- Inventory internet-facing UDP/500 and UDP/4500 endpoints; remove unused VPN listeners.
- Use detection-only fingerprinting in authorized scopes; do not run exploit modes against production.
- Monitor for anomalous IKEv2
IKE_SA_INITfloods from scanners. - Rotate secrets and review VPN configs if appliances lagged patches while exposed.
Sources
- Sploitus — WatchGuard CVE-2025-9242
- WatchGuard / vendor security advisories for Fireware CVE-2025-9242 (confirm current fixed builds)