Executive brief
WatchGuard Firebox appliances, which are used to secure corporate networks and provide encrypted VPN access, contain a critical security flaw. An attacker can exploit this vulnerability over the internet without any login credentials to take complete control of the device. This could lead to a total network compromise, data theft, or a complete shutdown of secure remote access services. This vulnerability is reportedly being exploited in the wild.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in the 'iked' process of WatchGuard Fireware OS. The flaw is triggered during the handling of IKEv2 packets and specifically affects configurations involving Mobile User VPN with IKEv2 or Branch Office VPN using IKEv2 with a dynamic gateway peer. A remote, unauthenticated attacker can exploit this by sending specially crafted packets to the VPN endpoint, leading to arbitrary code execution with high privileges. The vulnerability has been observed in active exploitation, and administrators should apply vendor-provided patches immediately.
Affected products
- WatchGuard Fireware OS 11.10.2 through 11.12.4_Update1, 12.0 through 12.11.3, and 2025.1
- WatchGuard Firebox Multiple models including M, T, NV, and Cloud/V series
Timeline
- 2025-09-17: disclosed: Initial CVE entry created by WatchGuard
- 2025-11-12: advisory: Vendor advisory and NVD publication
- 2025-11-12: kev added: Added to CISA Known Exploited Vulnerabilities catalog
- 2025-11-12: exploited: Confirmed active exploitation in the wild