An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer. If the Firebox was previously configured with the mobile user VPN with IKEv2 or a branch office VPN using IKEv2 to a dynamic gateway peer, and both of those configurations have since been deleted, that Firebox may still be vulnerable if a branch office VPN to a static gateway peer is still configured.
An out-of-bounds write error (CWE-787) occurs in IKEv2 protocol handling, which is used by both Mobile User VPN and Branch Office VPN configured with dynamic gateway peers. An attacker can send a specially crafted IKEv2 packet to the device without any authentication, leading to memory overwrite beyond the intended buffer. This results in the ability to hijack code execution flow in the Fireware operating system.
An attacker can remotely execute arbitrary code (RCE) with system privileges on a vulnerable WatchGuard Firebox device, leading to full compromise of the device, including control over network traffic passing through it.
Apply patches available from the vendor according to the references (WatchGuard advisory WGSA-2025-00015 at watchguard.com/wgrd-psirt/advisory/wgsa-2025-00015). Due to active exploitation of the vulnerability in attacks and availability of public exploit code, the update should be deployed immediately. If immediate patching is not possible, consider disabling or restricting access to IKEv2 VPN functionality from external networks.
WatchGuard Firebox T70, M440, M370, M690, M470 running Fireware OS versions: 11.10.2 to 11.12.4_Update1 inclusive, 12.0 to 12.11.3 inclusive, and 2025.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XWatchguard Fireboxcloud
HWWatchguardall versionsWatchguard Firebox M270
HWWatchguardall versionsWatchguard Firebox M290
HWWatchguardall versionsWatchguard Firebox M295
HWWatchguardall versionsWatchguard Firebox M370
HWWatchguardall versionsWatchguard Firebox M390
HWWatchguardall versionsWatchguard Firebox M395
HWWatchguardall versionsWatchguard Firebox M440
HWWatchguardall versionsWatchguard Firebox M4600
HWWatchguardall versionsWatchguard Firebox M470
HWWatchguardall versionsWatchguard Firebox M4800
HWWatchguardall versionsWatchguard Firebox M495
HWWatchguardall versionsWatchguard Firebox M5600
HWWatchguardall versionsWatchguard Firebox M570
HWWatchguardall versionsWatchguard Firebox M5800
HWWatchguardall versionsWatchguard Firebox M590
HWWatchguardall versionsWatchguard Firebox M595
HWWatchguardall versionsWatchguard Firebox M670
HWWatchguardall versionsWatchguard Firebox M690
HWWatchguardall versionsWatchguard Firebox M695
HWWatchguardall versionsWatchguard Firebox Nv5
HWWatchguardall versionsWatchguard Firebox T115 W
HWWatchguardall versionsWatchguard Firebox T125
HWWatchguardall versionsWatchguard Firebox T125 W
HWWatchguardall versionsWatchguard Firebox T145
HWWatchguardall versionsWatchguard Firebox T145 W
HWWatchguardall versionsWatchguard Firebox T15
HWWatchguardall versionsWatchguard Firebox T185
HWWatchguardall versionsWatchguard Firebox T20
HWWatchguardall versionsWatchguard Firebox T25
HWWatchguardall versions
CISA KEV — detailsi
- Vendori
- WatchGuard
- Producti
- Firebox
- Added to KEVi
- November 12, 2025
- Remediation deadline (US Federal)i
- December 3, 2025(overdue)
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
WatchGuard Firebox contains an out-of-bounds write vulnerability in the OS iked process that may allow a remote unauthenticated attacker to execute arbitrary code.
Related vulnerabilities
An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthentic...
RCE bez uwierzytelnienia w WatchGuard Firebox i XTM (FBX-22786)
WatchGuard Fireware OS contains a race condition leading to a use-after-free vulnerability in LDAP authenticat...
Integer overflow w WatchGuard Firebox/XTM umożliwiający RCE bez uwierzytelnienia
WatchGuard Firebox/XTM – zdalne usuwanie plików bez uwierzytelnienia