CVE-2025-11838: WatchGuard Fireware
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
A memory corruption vulnerability in WatchGuard Fireware OS may allow an unauthenticated attacker to trigger a Denial of Service (DoS) condition in the Mobile User VPN with IKEv2 and the Branch Office VPN using IKEv2 when configured with a dynamic gateway peer.
Affected products
- WatchGuard Fireware: from 2025.1, before 2025.1.3 (fixed in 2025.1.3); from 12.0.0, before 12.11.5 (fixed in 12.11.5)
Published 2025-12-04. Last modified 2026-09-25.