Description
A stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.
Published: 2026-08-27
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A stack‑based buffer overflow in the iked process of WatchGuard Fireware OS allows a remote attacker to send specially crafted network traffic and execute arbitrary code without authentication. The vulnerability results from improper handling of input that overflows a buffer on the stack, leading to control‑flow hijacking and potentially full system compromise. The effect on confidentiality, integrity, and availability is total, as an attacker who succeeds can take control of the device and disrupt network services.

Affected Systems

WatchGuard Fireware OS devices are affected, including versions prior to Fireware OS 2026.2.2, Fireware OS 12.12.2, and Fireware OS 12.5.20. All releases before these patches are vulnerable.

Risk and Exploitability

With a CVSS score of 9.3 the vulnerability is classified as critical. EPSS data is not available, but the CVE has not been listed in the CISA KEV catalog. The likely attack vector is remote network traffic directed at the iked service, and the flaw can be exploited by unauthenticated attackers who can craft packets that trigger a stack overflow and gain arbitrary code execution on the affected device.

Generated by OpenCVE AI on August 28, 2026 at 05:38 UTC.

Remediation

Vendor Solution

Fireware OS 2026.2.2, Fireware OS 12.12.2, Fireware OS 12.5.20


OpenCVE Recommended Actions

  • Upgrade Fireware OS to version 2026.2.2, 12.12.2, or 12.5.20 as appropriate for your deployment.
  • Restrict access to the iked service by applying firewall rules or network segmentation to prevent unauthenticated external traffic.
  • Monitor device logs for suspicious connection attempts to the iked port and enforce alerting on repeated failures or abnormal traffic patterns.

Generated by OpenCVE AI on August 28, 2026 at 05:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description A stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.
Title Fireware OS Pre-Authentication Stack Buffer Overflow in iked Allows Remote Code Execution
First Time appeared Watchguard
Watchguard fireware Os
Weaknesses CWE-121
CWE-129
CWE-191
CPEs cpe:2.3:a:watchguard:fireware_os:*:*:*:*:*:*:*:*
Vendors & Products Watchguard
Watchguard fireware Os
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Watchguard Fireware Os
cve-icon MITRE

Status: PUBLISHED

Assigner: WatchGuard

Published:

Updated: 2026-08-27T23:24:32.589Z

Reserved: 2026-08-07T20:06:03.527Z

Link: CVE-2026-19318

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-28T02:16:21.070

Modified: 2026-08-28T02:16:21.070

Link: CVE-2026-19318

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T05:45:04Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow

  • CWE-129

    Improper Validation of Array Index

  • CWE-191

    Integer Underflow (Wrap or Wraparound)