Worrying WatchGuard VPN bug could let hackers hijack your devices – here’s how to stay safe

  • CVE-2025-9242 allows unauthenticated remote code execution on WatchGuard Fireware devices
  • Vulnerability affects VPN configurations using IKEv2 with dynamic gateway peers
  • Businesses should patch affected versions and restrict internet access to essential devices only

WatchGuard Fireware, the operating system powering much of WatchGuard’s software, carried a critical severity vulnerability that allowed threat actors to execute arbitrary code remotely and essentially take over compromised devices, the company has warned.

The vulnerability is tracked as CVE-2025-9242, and was given a severity score of 9.3/10 (critical). It is described as an out-of-bounds write vulnerability that allows unauthenticated entities to execute arbitrary code.

“This vulnerability affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer,” WatchGuard explained in a recent security advisory.

Music to ransomware gangs’ ears

Versions 11.10.2 to 11.12.4_Update 1 were said to be affected, as well as versions 12.0 – 12.11.3 and 2025.1. FireGuard released patches, addressing the flaw in these versions:

2025.1 – Fixed in 2025.1.1
12.x – Fixed in 12.11.4
12.3.1 (FIPS-certified release) – Fixed in 12.3.1_Update3 (B722811)
12.5.x (T15 & T35 models) – Fixed in 12.5.13)
11.x – Reached end-of-life

In their analysis of the flaw, security researchers watchTowr described it as having “all the characteristics your friendly neighborhood ransomware gangs love to see” – it was found in an internet-connected device, can be exploited without authentication, and allows for remote malicious code execution.

Ransomware operators love targeting firewalls and routers since these serve as gateways for most internet traffic on a network.

They also focus on file servers and domain controllers, since encrypting them disrupts many users, as well as remote-access services like RDP, VPN gateways and exposed management ports of firewalls, backups, cloud storage and accounts, and network-attached storage (NAS).

To remain secure, businesses should limit internet access to only essential devices, keeping all others on the local network. They should also make sure all the software and hardware is updated, and that their employees are aware of the latest phishing and social engineering techniques.

Via The Hacker News

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

You might also like

Read more @ TechRadar

Latest posts

100-Day Money-Back Guarantee on all Miele Duoflex and Guard purchases

Miele is a much-loved designer and manufacturer of high-end domestic appliances, including ovens, vacuum cleaners, coffee machines, and a whole lot more. If you...

Spotify’s upgraded live events feed lets you follow your favorite live music venues, allowing you to discover lesser-known gigs in your area

Spotify is updating its Live Events feed with new venue listings, rolling out now to both Free and Premium subscribers You can follow your...

What is the release date for Gen V season 2 episode 8 on Prime Video?

The end is nigh for Gen V season 2. That's right, the series' latest finale is almost here and, while it's got a lot...

Napster returns as an AI companion for your MacBook – seriously

Napster returns as an AI gadget companyBuild your own AI teamWork with them directly through your MacBookImagine a co-worker or companion, staring at you...

I reviewed the Xerox C320 – and I finally found a laser that prints like an inkjet

SpecsType: Color laser printerFunctions: print onlyConnectivity: Ethernet, Wi-Fi, USBMax print speed: 33ppmMax paper size: A4/letterPrint quality: 600dpi (4,800dpi enhanced)Apple AirPrint: yesConsumables included: 4x setup...

It’s only been a few days since Windows 10’s demise, and the latest Windows 11 update is causing havoc

Microsoft's Windows Recovery Environment has a major bug after the latest update for Windows 11 25H2USB mice and keyboards are not working in Windows...

China claims the US NSA conducted cyberattacks on its national time center

China has accused the US of cyber-espionageChina's National Time Service Center was breached through security flaws in employee phonesThe two states have been pointing...

Attention audiobook lovers! You can get three books for just $3 / £3 with this seasonal Audible deal

Listen up, audiobook fans. I have a corker of a deal for you that means you can get a three-month Audible Premium Plus membership...

Quordle hints and answers for Tuesday, October 21 (game #1366)

Looking for a different day?A new Quordle puzzle appears at midnight each day for your time zone – which means that some people are...

NYT Connections hints and answers for Tuesday, October 21 (game #863)

Looking for a different day?A new NYT Connections puzzle appears at midnight each day for your time zone – which means that some people...