VYPR
Unrated severityNVD Advisory· Published Dec 4, 2025· Updated Dec 15, 2025

WatchGuard Firebox iked Memory Corruption Vulnerability

CVE-2025-11838

Description

A memory corruption vulnerability in WatchGuard Fireware OS may allow an unauthenticated attacker to trigger a Denial of Service (DoS) condition in the Mobile User VPN with IKEv2 and the Branch Office VPN using IKEv2 when configured with a dynamic gateway peer.

This vulnerability affects Fireware OS 12.6.1 up to and including 12.11.4 and 2025.1 up to and including 2025.1.2.

Affected products

2
  • Range: >=12.6.1 <=12.11.4, >=2025.1 <=2025.1.2
  • WatchGuard/Fireware OSv5
    Range: 12.6.1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.