Hello everyone! If you utilize a WatchGuard Firebox firewall, you should pay attention. WatchGuard just reported a significant issue in certain Firebox firewalls that could allow hackers to control it remotely. Sounds scary!
Fireware OS 12.5.x: T15, T35
Fireware OS 12.x: T20, T25, T40, T45, T55, T70, T80, T85, M270, M290, M370, M390, M470, M570, M590, M670, M690, M440, M4600, M4800, M5600, M5800, Firebox Cloud, Firebox NV5, FireboxV
Fireware OS 2025.1.x: T115-W, T125, T125-W, T145, T145-W, T185
If your model is included in this list, you should be taking action now.
What Is The Problem?
This problem, CVE-2025-9242 is caused by a bug in Fireware OS which hackers could exploit to execute malicious code on your firewall. It mainly impacts people using IKEv2 VPN. Don’t think this can’t happen to you because your configuration is secure - there are still IKEv2 VPN settings that could be exploited. It’s worth reviewing.Which Fireboxes Are Affected?
While not every model has this issue, quite a few do:Fireware OS 12.5.x: T15, T35
Fireware OS 12.x: T20, T25, T40, T45, T55, T70, T80, T85, M270, M290, M370, M390, M470, M570, M590, M670, M690, M440, M4600, M4800, M5600, M5800, Firebox Cloud, Firebox NV5, FireboxV
Fireware OS 2025.1.x: T115-W, T125, T125-W, T145, T145-W, T185
If your model is included in this list, you should be taking action now.
How To Fix It
The positive note – WatchGuard has already issued updates to solve the problem. Revised versions are listed below:- 12.3.1_Update3
- 12.5.13
- 12.11.4
- 2025.1.1