Impact
A stack-based buffer overflow in the iked process of WatchGuard Fireware OS allows a remote attacker, without authentication, to send crafted traffic that overflows a buffer and causes the VPN component to crash, resulting in a denial of service. This failure is a classic stack overflow (CWE-121) that could potentially lead to memory corruption and skipped processes (CWE-787).
Affected Systems
The vulnerability affects all versions of WatchGuard Fireware OS prior to the listed patch releases. The official fix is available in Fireware OS 2026.2.2, Fireware OS 12.12.2, and Fireware OS 12.5.20. Any installation of these earlier versions is susceptible to the flaw.
Risk and Exploitability
The CVSS score of 8.7 classifies this issue as high severity. The exploit requires no authentication and is delivered via specially crafted network traffic directed at the iked service, making it remotely exploitable from the Internet. With no exploit probability score reported and the vulnerability not listed in the CISA KEV catalog, the threat is significant but the likelihood of an immediate exploited attack remains uncertain. Nonetheless, the combination of a high CVSS score and remote unauthenticated trigger warrants prompt action.
OpenCVE Enrichment