An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer. If the Firebox was previously configured with the mobile user VPN with IKEv2 or a branch office VPN using IKEv2 to a dynamic gateway peer, and both of those configurations have since been deleted, that Firebox may still be vulnerable if a branch office VPN to a static gateway peer is still configured.
The vulnerability is a buffer overflow (out-of-bounds write, CWE-787) in the IKEv2 protocol handler component. The vulnerability is triggered by both Mobile User VPN with IKEv2 and Branch Office VPN with IKEv2 configured with a dynamic gateway peer. An attacker can send specially crafted IKEv2 packets without prior authentication, leading to memory corruption and potential device takeover.
An attacker can execute arbitrary code on the device with the privileges of the VPN handling process, which in practice means complete takeover of the edge device and control over network traffic protected by the WatchGuard Firebox.
Fireware OS must be immediately updated to a version higher than 11.12.4_Update1 (for 11.x branch), higher than 12.11.5 (for 12.x branch), or higher than 2025.1.3 (for 2025.1 branch), in accordance with the official WatchGuard PSIRT message (WGSA-2025-00027). Until the patch is applied, consider disabling the IKEv2 VPN function or restricting access to IKEv2 ports only to trusted IP addresses at the firewall level.
WatchGuard Firebox T70, M440, M370, M690, M470 running Fireware OS versions: 11.10.2 through 11.12.4_Update1 inclusive, 12.0 through 12.11.5 inclusive, and 2025.1 through 2025.1.3 inclusive, when Mobile User VPN with IKEv2 or Branch Office VPN with IKEv2 with dynamic gateway peer is configured.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:RedWatchguard Fireboxcloud
HWWatchguardall versionsWatchguard Firebox M270
HWWatchguardall versionsWatchguard Firebox M290
HWWatchguardall versionsWatchguard Firebox M295
HWWatchguardall versionsWatchguard Firebox M370
HWWatchguardall versionsWatchguard Firebox M390
HWWatchguardall versionsWatchguard Firebox M395
HWWatchguardall versionsWatchguard Firebox M440
HWWatchguardall versionsWatchguard Firebox M4600
HWWatchguardall versionsWatchguard Firebox M470
HWWatchguardall versionsWatchguard Firebox M4800
HWWatchguardall versionsWatchguard Firebox M495
HWWatchguardall versionsWatchguard Firebox M5600
HWWatchguardall versionsWatchguard Firebox M570
HWWatchguardall versionsWatchguard Firebox M5800
HWWatchguardall versionsWatchguard Firebox M590
HWWatchguardall versionsWatchguard Firebox M595
HWWatchguardall versionsWatchguard Firebox M670
HWWatchguardall versionsWatchguard Firebox M690
HWWatchguardall versionsWatchguard Firebox M695
HWWatchguardall versionsWatchguard Firebox Nv5
HWWatchguardall versionsWatchguard Firebox T115 W
HWWatchguardall versionsWatchguard Firebox T125
HWWatchguardall versionsWatchguard Firebox T125 W
HWWatchguardall versionsWatchguard Firebox T145
HWWatchguardall versionsWatchguard Firebox T145 W
HWWatchguardall versionsWatchguard Firebox T15
HWWatchguardall versionsWatchguard Firebox T185
HWWatchguardall versionsWatchguard Firebox T20
HWWatchguardall versionsWatchguard Firebox T25
HWWatchguardall versions
CISA KEV — detailsi
- Vendori
- WatchGuard
- Producti
- Firebox
- Added to KEVi
- December 19, 2025
- Remediation deadline (US Federal)i
- December 26, 2025(overdue)
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
WatchGuard Fireware OS iked process contains an out of bounds write vulnerability in the OS iked process. This vulnerability may allow a remote unauthenticated attacker to execute arbitrary code and affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer.
Related vulnerabilities
An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthentic...
RCE bez uwierzytelnienia w WatchGuard Firebox i XTM (FBX-22786)
WatchGuard Fireware OS contains a race condition leading to a use-after-free vulnerability in LDAP authenticat...
Integer overflow w WatchGuard Firebox/XTM umożliwiający RCE bez uwierzytelnienia
WatchGuard Firebox/XTM – zdalne usuwanie plików bez uwierzytelnienia