Impact
An out‑of‑bounds write occurs in the iked DHCP/DNS daemon of WatchGuard Fireware OS. A remote unauthenticated attacker can craft packets that overflow the heap allocation and execute arbitrary code in the privileged iked process. The flaw is a classic heap buffer overflow (CWE‑122) compounded by signed/unsigned conversions and integer overflows (CWE‑190 and CWE‑680). Successful exploitation results in full control of the device, compromising confidentiality, integrity, and availability.
Affected Systems
The vulnerability affects all versions of WatchGuard Fireware OS prior to the releases that contain the patch. WatchGuard recommends upgrading to Fireware OS 2026.2.2, 12.12.2, or 12.5.20. The affected product is the iked service running on the Fireware OS firmware. No specific release list is provided beyond the patched versions, so any older firmware is considered vulnerable.
Risk and Exploitability
With a CVSS score of 9.3 the flaw is of critical severity. The EPSS score is not available, and the vulnerability is not yet listed in the CISA KEV catalog. Attackers can exploit the weakness from anywhere on the network that can reach the iked port, without authentication or elevated privileges. Once the attacker delivers the malicious packet, arbitrary code execution is achieved on the device, providing a foothold for further lateral movement or service disruption.
OpenCVE Enrichment