CVE-2025-25249
Executive Summary
Fortinet FortiOS 7.6.0‑7.6.3, 7.4.0‑7.4.8, 7.2.0‑7.2.11, 7.0.0‑7.0.17, 6.4, and FortiSwitchManager 7.2.0‑7.2.6, 7.0.0‑7.0.5 contain a heap‑based buffer overflow that can be triggered by crafted packets. Attackers can achieve remote code execution or command execution. The vulnerability is actively exploited (CISA KEV).
Authoritative CVE Metadata - CVSS Base Score: 8.1 (HIGH) - Published: 2026-01-13T17:15:56.910 - Last Modified: 2026-09-09T20:17:20.720
[!CAUTION] Known Exploited Vulnerability: YES (CISA KEV Added: 2026-09-09)
Original Description: A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets
"I'm a great believer in luck and I find the harder I work, the more I have of it."
— Thomas Jefferson