Description
A type confusion vulnerability in the iked process of WatchGuard Fireware OS allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.
Published: 2026-08-27
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a type confusion error in the iked service of WatchGuard Fireware OS. An unauthenticated attacker can send crafted network packets that cause the service to misinterpret data types, enabling arbitrary code execution. This compromises confidentiality, integrity, and availability of the entire device, allowing full control over the appliance. The weakness aligns with CWE-125, CWE-763, and CWE-843.

Affected Systems

Affected are WatchGuard Fireware OS appliances running either the 12.5.20, 12.12.2, or 2026.2.2 firmware releases. All other versions are presumed vulnerable unless patched beyond these releases.

Risk and Exploitability

The CVSS score of 9.3 classifies this as a critical vulnerability. No EPSS data is currently available, and the flaw is not yet catalogued in CISA’s KEV list. The likely attack vector is remote network traffic to the iked port; no authentication is required. Successful exploitation would likely result in complete system compromise.

Generated by OpenCVE AI on August 28, 2026 at 05:36 UTC.

Remediation

Vendor Solution

Fireware OS 2026.2.2, Fireware OS 12.12.2, Fireware OS 12.5.20


OpenCVE Recommended Actions

  • Upgrade the device firmware to Fireware OS 2026.2.2, 12.12.2, or 12.5.20, depending on the installed release.
  • If a firmware upgrade cannot be performed immediately, block or restrict inbound network traffic to the iked service using firewall or segmentation rules to prevent unauthorized access.
  • Continuously monitor device logs for anomalous authentication failures or unusual traffic patterns that could indicate exploitation attempts.

Generated by OpenCVE AI on August 28, 2026 at 05:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description A type confusion vulnerability in the iked process of WatchGuard Fireware OS allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.
Title Fireware OS Pre-Authentication Type Confusion in iked Allows Remote Code Execution
First Time appeared Watchguard
Watchguard fireware Os
Weaknesses CWE-125
CWE-763
CWE-843
CPEs cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:*
Vendors & Products Watchguard
Watchguard fireware Os
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Watchguard Fireware Os
cve-icon MITRE

Status: PUBLISHED

Assigner: WatchGuard

Published:

Updated: 2026-08-27T23:24:33.721Z

Reserved: 2026-08-07T20:05:56.818Z

Link: CVE-2026-19315

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-28T02:16:20.703

Modified: 2026-08-28T02:16:20.703

Link: CVE-2026-19315

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T08:15:06Z

Weaknesses
  • CWE-125

    Out-of-bounds Read

  • CWE-763

    Release of Invalid Pointer or Reference

  • CWE-843

    Access of Resource Using Incompatible Type ('Type Confusion')