CVE-2025-11838: WatchGuard Firebox iked Memory Corruption Vulnerability
A memory corruption vulnerability in WatchGuard Fireware OS may allow an unauthenticated attacker to trigger a Denial of Service (DoS) condition in the Mobile User VPN with IKEv2 and the Branch Office VPN using IKEv2 when configured with a dynamic gateway peer.
This vulnerability affects Fireware OS 12.6.1 up to and including 12.11.4 and 2025.1 up to and including 2025.1.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11838?
CVE-2025-11838 is classified as a high severity vulnerability due to the potential for triggering a Denial of Service (DoS).
How do I fix CVE-2025-11838?
To fix CVE-2025-11838, update WatchGuard Fireware OS to the latest version that addresses the vulnerability.
What type of vulnerability is CVE-2025-11838?
CVE-2025-11838 is a memory corruption vulnerability that affects the Mobile User VPN and Branch Office VPN functionalities.
Who is affected by CVE-2025-11838?
CVE-2025-11838 affects users of WatchGuard Fireware OS versions between 12.0 and 12.11.4, as well as versions 2025.1 to 2025.1.2.
Can CVE-2025-11838 be exploited remotely?
Yes, CVE-2025-11838 can be exploited remotely by an unauthenticated attacker targeting the configurations with dynamic gateway peers.