Executive brief
WatchGuard Fireware OS is a firewall operating system that manages network security and VPN connections. A stack buffer overflow vulnerability in the iked process (IPsec daemon) allows an attacker from the network to send malicious traffic and execute arbitrary code without authentication, potentially compromising firewall operations and gaining control of the system.
Technical details
The vulnerability is a stack-based buffer overflow (CWE-121) in the WatchGuard Fireware OS iked process, combined with improper array index validation (CWE-129) and integer underflow issues (CWE-191). The iked process is responsible for IPsec key exchange and operates at the network edge. A remote, unauthenticated attacker can trigger the overflow by sending specially crafted network traffic to the IPsec service, leading to arbitrary code execution with the privileges of the iked process. Fixed in Fireware OS versions 2026.3.1, 2026.2.2, 12.12.2, and 12.5.20.
Affected products
- WatchGuard Fireware OS Default and T15/T35: 2025.0 to 2026.2.1, 12.0 to 12.12.1; T35: 2026.3 to 2026.3.0, 12.0 to 12.5.19
Timeline
- 2026-08-27: disclosed
- 2026-08-28: advisory
- 2026-08-27: patched: Patches available: Fireware OS 2026.3.1, 2026.2.2, 12.12.2, 12.5.20