CVE-2025-32756
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiCamera 1.1 all versions, FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail 7.0.0 through 7.0.8, FortiNDR 7.6.0, FortiNDR 7.4.0 through 7.4.7, FortiNDR 7.2.0 through 7.2.4, FortiNDR 7.0.0 through 7.0.6, FortiRecorder 7.2.0 through 7.2.3, FortiRecorder 7.0.0 through 7.0.5, FortiRecorder 6.4.0 through 6.4.5, FortiVoice 7.2.0, FortiVoice 7.0.0 through 7.0.6, FortiVoice 6.4.0 through 6.4.10 allows a remote unauthenticated attacker to execute arbitrary code or commands via sending HTTP requests with specially crafted hash cookie.
Affected (23)
Products: Fortinet: Fortimail, Fortindr, Fortirecorder, Fortivoice, Forticamera Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 7.0.0 to 7.0.9 | |
| From 7.0.0 to 7.0.7 | |
| From 6.4.0 to 6.4.6 | |
| From 6.4.0 to 6.4.11 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 2.0.0 to 2.1.3 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.1.0 to 1.1.5 |
| Running on/with | Platform Versions |
|---|---|
Fortinet Forticamera | All versions |
Related CWEs
CWE-121
Stack-based Buffer Overflow
A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).
CWE-787
Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
References (2)
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource
Timeline
No history available yet.