CVE-2025-9242
Exploited in the Wild
✓ Confirmed 0-Day
Triaged: March 5, 2026
3 articles
EPSS Score
Source: FIRST.org · 2026-05-24
73.48%
probability
This CVE has a 73.48% probability
of being exploited in the next 30 days.
0%
Top 98.8th percentile of all CVEs
100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE.
View on VulnerabilityLookup ↗
Attack Intelligence
Exploits & PoC
watchtowrlabs/watchTowr-vs-WatchGuard-CVE-2025-9242
PoC CVE-2025-9242 — watchtowrlabs/watchTowr-vs-WatchGuard-CVE-2025-9242
13
1 repo — triés par ⭐
Rechercher sur GitHub ↗
WatchGuard Warns of Active Exploitation of Critical Fireware OS VPN Vulnerability
TheHackerNews
Dec 19, 2025
CISA Flags Critical WatchGuard Fireware Flaw Exposing 54,000 Fireboxes to No-Login Attacks
TheHackerNews
Nov 13, 2025
Signal Intelligence
Confidence
85%
EPSS
73.48%
Mentions
3
Last Seen
Dec 19, 2025
CNA Information
Analyst Note
CVE-2025-9242 is a 2025 critical vulnerability in WatchGuard Fireware OS with documented active exploitation in real-world attacks. CISA added it to the KEV catalog based on evidence of active exploitation, and articles explicitly reference active real-world exploitation occurring alongside vendor patch release, meeting zero-day criteria.
Threat Actors 10
Hacking Team
apt_group
🇮🇹 IT
Watchdog
apt_group
🇨🇳 CN
HAZY TIGER
apt_group
Information theft and espionage
🇮🇳 IN
Infy
apt_group
Information theft and espionage
🇮🇷 IR
ArcaneDoor
apt_group
🇨🇳 CN
Returned Libra
apt_group
🇨🇳 CN
The White Company
apt_group
Information theft and espionage
🇨🇳 CN
Operation Red Signature
apt_group
Information theft and espionage
🇨🇳 CN
Shadow Network
apt_group
Information theft and espionage
🇨🇳 CN
Mana Team
apt_group
🇨🇳 CN
Triage Info
Decided atMar 05, 2026