Back

CRITICAL KEV Used in ransomware campaigns

WatchGuard Firebox iked Out of Bounds Write Vulnerability

Published Dec 19, 2025 ·Due Dec 26, 2025

Description

An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer.

If the Firebox was previously configured with the mobile user VPN with IKEv2 or a branch office VPN using IKEv2 to a dynamic gateway peer, and both of those configurations have since been deleted, that Firebox may still be vulnerable if a branch office VPN to a static gateway peer is still configured.

Affected products

Remediation

Vendor solution

Fireware OS 2025.1.4, Fireware OS 12.11.6, Fireware OS 12.5.15, Fireware OS 12.3.1-b728352 In addition to installing the latest Fireware OS that contains the fix, administrators that have confirmed threat actor activity on their Firebox appliances must take precautions to rotate all locally stored secrets on vulnerable Firebox appliances as described in our Best Practices to Rotate Shared Secrets Stored on the Firebox knowledge base article (https://techsearch.watchguard.com/KB?type=Article&SFDCID=kA1Vr000000DNMzKAO&lang=en_US).

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner WatchGuard
Published Dec 19, 2025
Updated Sep 9, 2026
Reserved Dec 15, 2025
CISA Vulnrichment
Updated Dec 20, 2025
NVD
Status Analyzed
Modified Sep 9, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner WatchGuard
Published Dec 19, 2025
Updated Sep 9, 2026
Exploited since Dec 19, 2025
EUVD-2025-204437