Impact
The vulnerability is a type confusion error in the iked service of WatchGuard Fireware OS. An unauthenticated attacker can send crafted network packets that cause the service to misinterpret data types, enabling arbitrary code execution. This compromises confidentiality, integrity, and availability of the entire device, allowing full control over the appliance. The weakness aligns with CWE-125, CWE-763, and CWE-843.
Affected Systems
Affected are WatchGuard Fireware OS appliances running either the 12.5.20, 12.12.2, or 2026.2.2 firmware releases. All other versions are presumed vulnerable unless patched beyond these releases.
Risk and Exploitability
The CVSS score of 9.3 classifies this as a critical vulnerability. No EPSS data is currently available, and the flaw is not yet catalogued in CISA’s KEV list. The likely attack vector is remote network traffic to the iked port; no authentication is required. Successful exploitation would likely result in complete system compromise.
OpenCVE Enrichment