Fireware OS Pre-Authentication Stack Buffer Overflow in iked Allows Remote Code Execution
Summary #
A stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.
Impact: An unauthenticated remote attacker who completes IKE_SA_INIT can send a specially crafted IKE_AUTH message containing an EAP-MSCHAPv2 payload with an undersized embedded length field, triggering a stack buffer overflow in the iked process. This causes a crash and denial-of-service condition (with automatic respawn), and given the attacker-influenced nature of the stack overwrite, may carry potential for remote code execution. Exploitation requires that IKE payload diagnostic logging, a supported operational troubleshooting setting, be enabled on the affected device.
Product status #
| Product | Affected | Not affected |
|---|---|---|
| Fireware OS | ||
| Default | >= 2025.0, < 2026.2.2, >= 12.0, < 12.12.2 | >= 2026.2.2, >= 12.12.2 |
| T15/T35 | >= 12.0, < 12.5.20 | >= 12.5.20 |
Weakness Type and Impact #
Exploitation Status #
Solution #
References #
Credits #
- McCaulay Hudson (@_McCaulay) of watchTowrfinder