WatchGuard Firebox iked Memory Corruption Vulnerability
CVE-2025-11838

8.7HIGH

Key Information:

Vendor

Watchguard

Vendor
CVE Published:
4 December 2025

What is CVE-2025-11838?

A memory corruption vulnerability in WatchGuard Fireware OS may allow an unauthenticated attacker to trigger a Denial of Service (DoS) condition in the Mobile User VPN with IKEv2 and the Branch Office VPN using IKEv2 when configured with a dynamic gateway peer.

This vulnerability affects Fireware OS 12.0 up to and including 12.11.4 and 2025.1 up to and including 2025.1.2.

Affected Version(s)

Fireware OS 12.0 <= 12.11.4

Fireware OS 2025.1 <= 2025.1.2

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

McCaulay Hudson (@_McCaulay) of watchTowr
.
CVE-2025-11838 : Memory Corruption Vulnerability in WatchGuard Fireware OS