ZeroHour

CVE-2026-78010

large

Stack Buffer Overflow in WatchGuard Fireware OS iked Process Enables VPN DoS

CVSS 4.0
8.7 high
EPSS
<1%p26
Published
()
Modified
AI analysis

A stack-based buffer overflow (CWE-121, with out-of-bounds write and improper input-length validation) exists in the iked process of WatchGuard's Fireware OS. A remote, unauthenticated attacker can trigger it by sending specially crafted network traffic to the appliance's IKE/VPN processing, causing a denial-of-service condition in VPN handling. The impact is availability only — CVSS 4.0 scores confidentiality and integrity impact as none — so current scoring indicates no data exposure or code execution from this flaw. Any organization running a WatchGuard Firebox/firewall on an affected Fireware OS release with IKE-based VPN processing enabled is affected; the provided data does not specify affected version ranges. The flaw is not currently known to be exploited: EPSS is 0.3% (26th percentile), it is not in CISA KEV, and no public proof-of-concept is known.

What to do: Upgrade Fireware OS to the fixed release cited in WatchGuard's advisory (no version numbers appear in the current data, so confirm affected and fixed versions there). As an interim mitigation, restrict IKEv2/IPsec endpoint exposure to trusted source addresses or disable IKEv2 Mobile VPN where it is not needed, and watch for VPN service (iked) restarts or unavailability that would indicate attempted exploitation.

Affected
WatchGuard Fireware OS
Estimated exposure
large≈10,000–100,000 internet-exposed Firebox appliances plausibly running IKE-based VPN (order-of-magnitude estimate; exact VPN-exposed subset unknown) — WatchGuard Firebox is a widely deployed SMB/mid-market firewall line with an installed base commonly cited in the hundreds of thousands to over a million units, and public internet scans regularly index tens of thousands of WatchGuard…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process iallows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic.

Weakness
CWE-121, CWE-787, CWE-1284
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.