Impact
A null pointer dereference exists in the IKEv2 (iked) process of WatchGuard Fireware OS, enabling a remote unauthenticated attacker to send specially crafted IKEv2 messages that crash the VPN daemon and trigger a denial‑of‑service condition. The flaw is a classic CWE‑476 null pointer dereference and impacts only the VPN service, interrupting connectivity for users.
Affected Systems
The vulnerability affects WatchGuard Fireware OS versions 11.10.2 through 11.12.4_Update1, 12.0 through 12.12, and 2025.1 through 2026.2. Both the Mobile User susceptible.
Risk and Exploitability
The the flaw as high severity, while the EPSS score of less than 1% indicates a very low exploitation probability. The vulnerability is not listed in CISA KEV, meaning no confirmed exploits have been observed. Attackers need only send untrusted IKEv2 traffic to a vulnerable VPN endpoint, no authentication is required, making the attack vector remote and straightforward.
OpenCVE Enrichment