Executive brief
WatchGuard Firebox appliances, which are used to secure corporate networks and provide encrypted remote access, contain a critical security flaw in their VPN handling process. An unauthorized person can exploit this weakness over the internet to take full control of the device. This could lead to a total network compromise, data theft, or a complete shutdown of secure remote connections. This vulnerability is reportedly being exploited in the wild.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in the 'iked' process of WatchGuard Fireware OS. The flaw is triggered during the handling of IKEv2 protocol messages. It specifically impacts Mobile User VPN with IKEv2 and Branch Office VPN using IKEv2 when configured with a dynamic gateway peer. A remote, unauthenticated attacker can exploit this by sending specially crafted packets to the device, leading to arbitrary code execution with high privileges. The vulnerability has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation. Patches are available in Fireware OS versions 12.11.6, 12.5.15, and 2025.1.4.
Affected products
- WatchGuard Fireware OS 11.10.2 to 11.12.4_Update1, 12.0 to 12.11.5, 2025.1 to 2025.1.3
- WatchGuard Firebox Multiple models including M, T, NV, Cloud, and V series
Timeline
- 2025-12-18: disclosed: Initial disclosure by WatchGuard
- 2025-12-18: advisory: Vendor advisory WGSA-2025-00027 published
- 2025-12-19: kev added: Added to CISA Known Exploited Vulnerabilities catalog