Close Menu
  • Home
  • Opinion
  • Region
    • Africa
    • Asia
    • Europe
    • Middle East
    • North America
    • Oceania
    • South America
  • AI & Machine Learning
  • Robotics & Automation
  • Space & Deep Tech
  • Web3 & Digital Economies
  • Climate & Sustainability Tech
  • Biotech & Future Health
  • Mobility & Smart Cities
  • Global Tech Pulse
  • Cybersecurity & Digital Rights
  • Future of Work & Education
  • Trend Radar & Startup Watch
  • Creator Economy & Culture
What's Hot

The McDonald’s AI Christmas Advert That Left Everybody Chilly

December 9, 2025

Dreame V50 Moist & Dry Twin Cleansing Vacuum – Tech Jio

December 9, 2025

How Payd makes earnings native for freelancers

December 9, 2025
Facebook X (Twitter) Instagram LinkedIn RSS
NextTech NewsNextTech News
Facebook X (Twitter) Instagram LinkedIn RSS
  • Home
  • Africa
  • Asia
  • Europe
  • Middle East
  • North America
  • Oceania
  • South America
  • Opinion
Trending
  • The McDonald’s AI Christmas Advert That Left Everybody Chilly
  • Dreame V50 Moist & Dry Twin Cleansing Vacuum – Tech Jio
  • How Payd makes earnings native for freelancers
  • Egypt and Iran Set to Play in 2026 World Cup ‘Delight Match’ in Seattle
  • Consultants on suggestions for aspiring entrepreneurs
  • Manycore Tech Inc. Unveils Strategic Roadmap, Opens Spatial-Intelligence Capabilities, and Launches Two New Merchandise
  • Deloitte confirms Vodacom Safaricom deal honest to shareholders
  • Canadians can now watch music movies on Spotify
Tuesday, December 9
NextTech NewsNextTech News
Home - Cybersecurity & Digital Rights - CISA Flags Important WatchGuard Fireware Flaw Exposing 54,000 Fireboxes to No-Login Assaults
Cybersecurity & Digital Rights

CISA Flags Important WatchGuard Fireware Flaw Exposing 54,000 Fireboxes to No-Login Assaults

NextTechBy NextTechNovember 16, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Follow Us
Google News Flipboard
CISA Flags Important WatchGuard Fireware Flaw Exposing 54,000 Fireboxes to No-Login Assaults
Share
Facebook Twitter LinkedIn Pinterest Email


Nov 13, 2025Ravie LakshmananVulnerability / Community Safety

The U.S. Cybersecurity and Infrastructure Safety Company (CISA) on Wednesday added a important safety flaw impacting WatchGuard Fireware to its Recognized Exploited Vulnerabilities (KEV) catalog, primarily based on proof of energetic exploitation.

The vulnerability in query is CVE-2025-9242 (CVSS rating: 9.3), an out-of-bounds write vulnerability affecting Fireware OS 11.10.2 as much as and together with 11.12.4_Update1, 12.0 as much as and together with 12.11.3 and 2025.1. It was patched by WatchGuard in September.

“WatchGuard Firebox incorporates an out-of-bounds write vulnerability within the OS iked course of which will enable a distant unauthenticated attacker to execute arbitrary code,” CISA stated in an advisory.

Particulars of the vulnerability have been shared by watchTowr Labs final month, with the cybersecurity firm stating that the problem stems from a lacking size test on an identification buffer used through the IKE handshake course of.

CIS Build Kits

“The server does try certificates validation, however that validation occurs after the susceptible code runs, permitting our susceptible code path to be reachable pre-authentication,” safety researcher McCaulay Hudson famous.

In an replace to its advisory on October 21, 2025, WatchGuard stated it has proof suggesting energetic exploitation of the flaw, sharing three indicators of compromise (IoCs) related to the exercise –

  • An IKE_AUTH request log message with an abnormally giant IKE_AUTH request IDi payload larger than 100 bytes
  • Throughout a profitable exploit, the iked course of will grasp, interrupting VPN connections
  • After a failed or profitable exploit, the iked course of will crash and generate a fault report on the Firebox

Based on information from the Shadowserver Basis, greater than 54,300 Firebox cases stay susceptible to the important bug as of November 12, 2025, down from a excessive of 75,955 on October 19.

1000033717
Variety of uncovered WatchGuard Firebox cases

Roughly 18,500 of those units are within the U.S., the scans reveal. Italy (5,400), the U.Ok. (4,000), Germany (3,600), and Canada (3,000) spherical up the highest 5. Federal Civilian Government Department (FCEB) businesses are suggested to use WatchGuard’s patches by December 3, 2025.

The event comes as CISA additionally added CVE-2025-62215 (CVSS rating: 7.0), a not too long ago disclosed flaw in Home windows kernel, and CVE-2025-12480 (CVSS rating: 9.1), an improper entry management vulnerability in Gladinet Triofox, to the KEV catalog. Google’s Mandiant Risk Protection workforce has attributed the exploitation of CVE-2025-12480 to a risk actor it tracks as UNC6485.

(The story was up to date after publication to incorporate data from WatchGuard confirming energetic exploitation efforts.)

Elevate your perspective with NextTech Information, the place innovation meets perception.
Uncover the newest breakthroughs, get unique updates, and join with a worldwide community of future-focused thinkers.
Unlock tomorrow’s traits immediately: learn extra, subscribe to our publication, and turn into a part of the NextTech group at NextTech-news.com

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
NextTech
  • Website

Related Posts

Apache Points Max-Severity Tika CVE After Patch Miss

December 9, 2025

Privateness issues raised as Grok AI discovered to be a stalker’s greatest good friend

December 8, 2025

GISEC GLOBAL 2026

December 8, 2025
Add A Comment
Leave A Reply Cancel Reply

Economy News

The McDonald’s AI Christmas Advert That Left Everybody Chilly

By NextTechDecember 9, 2025

December begins with equal elements snowflakes and fear. Households are scrambling to complete décor, dinners…

Dreame V50 Moist & Dry Twin Cleansing Vacuum – Tech Jio

December 9, 2025

How Payd makes earnings native for freelancers

December 9, 2025
Top Trending

The McDonald’s AI Christmas Advert That Left Everybody Chilly

By NextTechDecember 9, 2025

December begins with equal elements snowflakes and fear. Households are scrambling to…

Dreame V50 Moist & Dry Twin Cleansing Vacuum – Tech Jio

By NextTechDecember 9, 2025

Cordless wet-and-dry vacuums have develop into a staple for contemporary Singapore properties,…

How Payd makes earnings native for freelancers

By NextTechDecember 9, 2025

Precise numbers are exhausting to return by, however estimates counsel round 80…

Subscribe to News

Get the latest sports news from NewsSite about world, sports and politics.

NEXTTECH-LOGO
Facebook X (Twitter) Instagram YouTube

AI & Machine Learning

Robotics & Automation

Space & Deep Tech

Web3 & Digital Economies

Climate & Sustainability Tech

Biotech & Future Health

Mobility & Smart Cities

Global Tech Pulse

Cybersecurity & Digital Rights

Future of Work & Education

Creator Economy & Culture

Trend Radar & Startup Watch

News By Region

Africa

Asia

Europe

Middle East

North America

Oceania

South America

2025 © NextTech-News. All Rights Reserved
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms Of Service
  • Advertise With Us
  • Write For Us
  • Submit Article & Press Release

Type above and press Enter to search. Press Esc to cancel.

Subscribe For Latest Updates

Sign up to best of Tech news, informed analysis and opinions on what matters to you.

Invalid email address
 We respect your inbox and never send spam. You can unsubscribe from our newsletter at any time.     
Thanks for subscribing!