← Back

CVE-2025-54820

nvd nist
Published: Mar 10, 2026Modified: Jun 17, 2026

JSON object

Loading...
8.1
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 5.9
Source: psirt@fortinet.com (Secondary)

Description

A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiManager 7.4.0 through 7.4.2, FortiManager 7.2.0 through 7.2.10, FortiManager 6.4 all versions may allow a remote unauthenticated attacker to execute unauthorized commands via crafted requests, if the service is enabled. The success of the attack depends on the ability to bypass the stack protection mechanisms.

Affected (2)

1 product
Fortimanager
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Fortinet
From 6.4.0 to 7.2.11
From 7.4.0 to 7.4.3

References (1)

Source: psirt@fortinet.com
Vendor Advisory

Timeline

No history available yet.