WatchGuard Vulnerability Allows Code Execution by Unauthenticated Attackers
WatchGuard has issued an advisory regarding a critical vulnerability, CVE-2025-9242, in its Firebox network security appliances that could allow unauthenticated attackers to execute arbitrary code. Affecting various Fireware OS versions, the flaw is particularly concerning for organizations utilizing mobile and branch office VPN configurations. With a CVSS score of 9.3, the vulnerability poses a significant risk, and WatchGuard has rolled out firmware updates to mitigate the issue. Administrators are urged to upgrade to the latest versions and implement network hardening measures to minimize exposure, such as restricting IKEv2 traffic to known IP addresses. This incident underscores the importance of timely software updates and proactive security measures in safeguarding network infrastructure against potential threats.