Impact
The vulnerability is a race condition that leads to a use‑after‑free in the LDAP authentication path used by the Mobile User VPN with IKEv2 on WatchGuard Fireware OS. An attacker that can trigger the flaw could execute arbitrary code as the iked process, effectively taking control over the Firebox. The flaw is classified as CWE‑416 and poses a high‑severity code‑execution risk that could compromise device integrity and availability.
Affected Systems
Affected system information is limited to Fireware OS releases 11.0 through 11.12.4_Update1, 12.0 through 12.12, and 2025.1 through 2026.2. Only devices that have Mobile VPN with IKEv2 configured to use an external LDAP authentication server are exposed; firmware versions newer than those or configurations without this feature are not vulnerable.
Risk and Exploitability
CVSS 9.2 indicates critical severity. EPSS less than 1% indicates a low current exploitation probability, but the remote, unauthenticated nature of the attack means an adversary could trigger the flaw by accessing the VPN and interacting with the LDAP authentication handshake. The exact mechanism of sending crafted LDAP messages is inferred from the description because the CVE text does not explicitly describe the attack vector; it only states a use‑after‑free that can lead to code execution. The vulnerability is not catalogued in CISA KEV, but its high severity and potential for full device takeover make it a top priority for mitigations.
OpenCVE Enrichment