CVE-2025-11838: high-severity vulnerability in WatchGuard Fireware OS
WatchGuard Firebox iked Memory Corruption Vulnerability
Published · Updated
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.7epss 0.5%
exploitation probability
0.5%top 59% of all CVEs
observed exploitation
nono source reports it
A memory corruption vulnerability in WatchGuard Fireware OS may allow an unauthenticated attacker to trigger a Denial of Service (DoS) condition in the Mobile User VPN with IKEv2 and the Branch Office VPN using IKEv2 when configured with a dynamic gateway peer.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Affected products
WatchGuard · Fireware OSRelated CVEs — WatchGuard Fireware OS
In the same product, most dangerous first.
CVE-2025-9242CRITICALWatchGuard Firebox iked Out of Bounds Write VulnerabilityEPSS 91.3%KEVCVE-2025-14733CRITICALWatchGuard Firebox iked Out of Bounds Write VulnerabilityEPSS 26.5%KEVCVE-2022-31749MEDIUMAuthenticated arbitrary file read/write in WatchGuard Fireware OSEPSS 1.3%CVE-2026-3987HIGHWatchGuard Firebox Arbitrary File Write vis Path Traversal in Fireware Web UIEPSS 1.1%CVE-2024-5974HIGHFirebox Authenticated Buffer Overflow VulnerabilityEPSS 1.1%CVE-2026-13368CRITICALWatchGuard Firebox Race Condition and Use-After-Free in Mobile VPN with IKEv2 LDAP AuthenticationEPSS 0.9%