← Back

CVE-2025-46776

nvd nist
Published: Nov 18, 2025Modified: Jun 17, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiExtender 7.6.0 through 7.6.1, FortiExtender 7.4.0 through 7.4.6, FortiExtender 7.2 all versions, FortiExtender 7.0 all versions may allow an authenticated user to execute arbitrary code or commands via crafted CLI commands.

Affected (2)

1 product
Fortiextender Firmware
Configuration A
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Fortinet
From 7.0.0 to 7.4.8
From 7.6.0 to 7.6.3
Running on/withPlatform Versions
Fortinet
Fortiextender
All versions

References (1)

Source: psirt@fortinet.com
Vendor Advisory

Timeline

No history available yet.