Impact
The vulnerability is an out-of-bounds read in the iked process of WatchGuard Fireware OS. An attacker who can send crafted network packets, even without authentication, can trigger a buffer overread that causes the VPN processing to crash, resulting in a Denial of Service. The weakness is reflected in the common weakness enumerations CWE-125 and CWE-20, indicating improper bounds checking and general input validation flaws.
Affected Systems
WatchGuard Fireware OS devices running unpatched versions prior to the releases 2026.2.2, 12.12.2, or 12.5.20 are impacted. The Fireware OS platform includes all watchguard:fireware_os endpoints.
Risk and Exploitability
With a CVSS score of 8.7 the impact rating is high and the vulnerability is exploitable by any remote host that can contact the VPN port. While the EPSS score is not available, the absence of a KEV listing does not reduce the urgency; the attack vector is remote unauthenticated using crafted traffic, and the DoS effect can disrupt network connectivity for affected devices.
OpenCVE Enrichment