WatchGuard Fireware OS contains a race condition leading to a use-after-free vulnerability in LDAP authentication for the Mobile User VPN with IKEv2. A remote unauthenticated attacker could exploit this vulnerability to execute arbitrary code in the context of the iked process on Fireboxes that have a Mobile VPN with IKEv2 configured to use an external LDAP authentication server.
The vulnerability is triggered by a race condition in the code handling LDAP authentication during IKEv2 connection negotiation. Due to thread racing, a use-after-free condition occurs (CWE-416), where the iked process references a memory area that has already been freed. An attacker can craft appropriate network traffic directed at the IKEv2 VPN interface to trigger this anomaly and gain control of code execution in the context of the iked process. A necessary condition is configuring Mobile VPN with IKEv2 to use an external LDAP authentication server.
An attacker can execute arbitrary code (RCE) in the context of the iked process on the Firebox device, which may lead to complete takeover of the VPN process, disclosure of sensitive authentication credentials, or further compromise of network infrastructure.
Patches available from the vendor should be applied according to the references (advisory WGSA-2026-00023 at https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00023). Until an update is applied, it is recommended to disable Mobile VPN with IKEv2 or change the authentication method from external LDAP to another method, if operationally feasible.
WatchGuard Fireware OS in versions: 11.0 to 11.12.4_Update1 inclusive, 12.0 to 12.12 inclusive, and 2025.1 to 2026.2 inclusive — on Firebox devices with active Mobile VPN with IKEv2 configuration and external LDAP server
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XWatchguard Firebox Cloud
APPWatchguardall versionsWatchguard Firebox M270
HWWatchguardall versionsWatchguard Firebox M290
HWWatchguardall versionsWatchguard Firebox M295
HWWatchguardall versionsWatchguard Firebox M370
HWWatchguardall versionsWatchguard Firebox M390
HWWatchguardall versionsWatchguard Firebox M395
HWWatchguardall versionsWatchguard Firebox M440
HWWatchguardall versionsWatchguard Firebox M4600
HWWatchguardall versionsWatchguard Firebox M470
HWWatchguardall versionsWatchguard Firebox M4800
HWWatchguardall versionsWatchguard Firebox M495
HWWatchguardall versionsWatchguard Firebox M5600
HWWatchguardall versionsWatchguard Firebox M570
HWWatchguardall versionsWatchguard Firebox M5800
HWWatchguardall versionsWatchguard Firebox M590
HWWatchguardall versionsWatchguard Firebox M595
HWWatchguardall versionsWatchguard Firebox M670
HWWatchguardall versionsWatchguard Firebox M690
HWWatchguardall versionsWatchguard Firebox M695
HWWatchguardall versionsWatchguard Firebox Nv5
HWWatchguardall versionsWatchguard Firebox T115 W
HWWatchguardall versionsWatchguard Firebox T125
HWWatchguardall versionsWatchguard Firebox T125 W
HWWatchguardall versionsWatchguard Firebox T145
HWWatchguardall versionsWatchguard Firebox T145 W
HWWatchguardall versionsWatchguard Firebox T15
HWWatchguardall versionsWatchguard Firebox T185
HWWatchguardall versionsWatchguard Firebox T20
HWWatchguardall versionsWatchguard Firebox T25
HWWatchguardall versions
Related vulnerabilities
An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthentic...
An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthentic...
RCE bez uwierzytelnienia w WatchGuard Firebox i XTM (FBX-22786)
Integer overflow w WatchGuard Firebox/XTM umożliwiający RCE bez uwierzytelnienia
WatchGuard Firebox/XTM – zdalne usuwanie plików bez uwierzytelnienia