← Back

CVE-2025-25249

nvd nist
Published: Jan 13, 2026Modified: Jun 17, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets

Affected (9)

3 products
Fortios
Fortiswitchmanager
Fortisase
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Fortinet
From 6.4.0 to 6.4.17
From 7.0.0 to 7.0.18
From 7.2.0 to 7.2.12
From 7.4.0 to 7.4.9
From 7.6.0 to 7.6.4
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Fortinet
From 7.0.0 to 7.0.6
From 7.2.0 to 7.2.7
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Fortinet
Version 25.1.39
Version 25.1.51

References (2)

Source: psirt@fortinet.com
Vendor Advisory
Source: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e

Timeline

No history available yet.