CVE-2025-9242 is a CWE-787 out-of-bounds write vulnerability in the iked Internet Key Exchange daemon in WatchGuard Fireware OS on Firebox appliances. A remote unauthenticated attacker can send malicious IKEv2 traffic to corrupt memory and execute arbitrary code. The affected attack surface includes Mobile User VPN using IKEv2 and Branch Office VPN using IKEv2 with a dynamic gateway peer. Fireboxes that formerly used either affected configuration can remain vulnerable after its deletion when a Branch Office VPN to a static gateway peer remains configured.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (4 hidden).
Repository contains a standalone Python exploit package for CVE-2025-9242 targeting WatchGuard Fireware 12.7 build 640389 with an M270-specific archived profile. Structure is minimal: README/NOTICE/MANIFEST metadata, requirements.txt, a large protocol/exploit engine (engine.py), and a CLI wrapper (wg_cve_2025_9242.py). The CLI exposes three modes: detect, analyze, and exploit. Detect performs a non-overflowing IKEv2 IKE_SA_INIT exchange to fingerprint firmware/build without sending the documented 513-byte trigger. Analyze is offline-only and builds the reverse-shell shellcode plus final payload for validation/hashing. Exploit first repeats exact-version/build detection, then—only if the target matches 12.7/640389 and the operator supplies explicit confirmation flags—builds and sends a pre-authentication RCE payload. The engine implements IKEv2 protocol handling, version/build fingerprint extraction, and a version-pinned ROP chain. The included gadget table and comments show the exploit is tailored to a specific Fireware build, using GOT-based resolution of mprotect, runtime page alignment, and a jump into attacker-supplied shellcode. The runtime payload is generated with pwntools as amd64 Linux shellcode that executes /usr/bin/python with inline Python code to connect back to an operator-supplied IPv4 callback, send uid/euid, redirect stdio, and spawn an interactive interpreter. Overall, this is a real active exploit rather than a detector-only script; it is operational but narrowly scoped to one exact target profile and includes safety gating to reduce accidental misuse.
This repository contains a Python exploit script (watchTowr-vs-WatchGuard-CVE-2025-9242.py) and a README.md. The exploit targets WatchGuard Firebox/WatchGuard OS devices vulnerable to CVE-2025-9242, an unauthenticated remote code execution vulnerability in the IKEv2 service. The script can both detect vulnerable firmware versions and, if instructed, deliver a custom ROP chain and shellcode payload to achieve code execution. The exploit operates over the network, targeting UDP port 500 (IKEv2) on the remote device. The README provides usage instructions, affected versions, and example command lines. The code is operational, with hardcoded ROP gadgets for specific firmware versions, and requires the attacker to specify both the target and local host/port for exploitation. No external C2 or hardcoded domains are present; all endpoints are user-supplied or local. The repository is focused, with clear separation between documentation and exploit code.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
167 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A prior, near-identical pre-auth remote code execution vulnerability in WatchGuard Firebox, referenced as evidence of a recurring out-of-bounds-write issue in the same code path.
A WatchGuard Firebox remote-code-execution vulnerability nearly identical to CVE-2025-14733. It was patched by WatchGuard and subsequently designated by CISA as actively exploited.
A remotely exploitable code-execution vulnerability in WatchGuard Firebox firewalls, nearly identical to CVE-2025-14733. It was patched by WatchGuard and subsequently designated by CISA as actively exploited.
Referenced only as a nuclei template whose CPE format was corrected by adding a missing 13th field.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.