A type confusion vulnerability in the iked process of WatchGuard Fireware OS allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.
This vulnerability is exploitable on systems where the Mobile VPN with IKEv2 or a Branch Office VPN with IKEv2 is configured.
WatchGuard is not aware of any exploitation of this vulnerability in the wild.
Fireware OS 2026.2.2, Fireware OS 12.12.2, Fireware OS 12.5.20