CRITICAL

CVE-2025-25249

Fortinet Fortios 2026-01-13 CVSS v3.1
CVSS
9.8
KEV

Description

A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets

Summary dbcve.org

A heap-based buffer overflow vulnerability in FortiOS and FortiSwitchManager allows remote attackers to execute arbitrary code or commands by sending specially crafted packets to the affected system. The overflow occurs in heap memory, potentially allowing attackers to overwrite function pointers or other critical data structures to gain code execution.

Mitigation

Apply the vendor-supplied Fortinet patch or upgrade to a fixed version of FortiOS/FortiSwitchManager. If immediate patching is not feasible, restrict network access to management interfaces and implement IPS/IDS signatures as an interim control.

Proof of Concept

Weakness (CWE)

CWE-122 Heap-based Buffer Overflow
CWE-787 Out-of-bounds Write

EPSS Score

2.4%
Probability of exploitation in next 30 days
83.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE