CRITICAL

CVE-2025-32756

Fortinet Fortimail 2025-05-13 CVSS v3.1
CVSS
9.8
KEV

Description

A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiCamera 1.1 all versions, FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail 7.0.0 through 7.0.8, FortiNDR 7.6.0, FortiNDR 7.4.0 through 7.4.7, FortiNDR 7.2.0 through 7.2.4, FortiNDR 7.0.0 through 7.0.6, FortiRecorder 7.2.0 through 7.2.3, FortiRecorder 7.0.0 through 7.0.5, FortiRecorder 6.4.0 through 6.4.5, FortiVoice 7.2.0, FortiVoice 7.0.0 through 7.0.6, FortiVoice 6.4.0 through 6.4.10 allows a remote unauthenticated attacker to execute arbitrary code or commands via sending HTTP requests with specially crafted hash cookie.

Summary dbcve.org

Stack-based buffer overflow (CWE-121) in FortiCamera, FortiMail, FortiNDR, FortiRecorder, and FortiVoice allows remote unauthenticated attackers to execute arbitrary code via HTTP requests containing specially crafted hash cookies. The critical CVSS 9.8 score reflects the severe impact of unauthenticated remote code execution.

Mitigation

Apply vendor-supplied patches for all affected products: FortiCamera (upgrade to latest), FortiMail (7.6.3+, 7.4.5+, 7.2.8+, 7.0.9+), FortiNDR (upgrade to latest), FortiRecorder (7.2.4+, 7.0.6+, 6.4.6+), FortiVoice (7.2.1+, 7.0.7+, 6.4.11+). Until patched, restrict network access to these services.

Weakness (CWE)

CWE-121 Stack-based Buffer Overflow
CWE-787 Out-of-bounds Write

EPSS Score

29.81%
Probability of exploitation in next 30 days
98.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE