Impact
An out‑of‑bounds write flaw exists in the ikestubd daemon of WatchGuard Fireware OS. The vulnerability can be triggered by a specially crafted request sent to the Management Web UI. When executed, the memory corruption allows an attacker to run arbitrary code on the device with the privileges of the ikestubd process. The risk to confidentiality, integrity, and availability is classified as high, reflected by a CVSS score of 8.6.
Affected Systems
Fireware OS releases 12.1 through 12.12 and 2025.1 through 2026.2 are affected. Devices running these versions expose the Management Web UI and run the ikestubd process to provide infrastructure services.
Risk and Exploitability
Exploitation requires an authenticated privileged user with access to the Management Web UI; the flaw is not remotely exploitable by unauthenticated users. The EPSS score is less than 1%, implying a low but measurable exploitation probability. The vulnerability is not listed in CISA’s KEV catalog, so no public exploits are known. If an attacker successfully authenticates with elevated privileges, they could achieve arbitrary code execution on the device.
OpenCVE Enrichment