CVE-2025-25249

A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, F

Severity
High 7.4
CVSS 3.1
Exploited
Yes — in CISA KEV
Added Sep 9, 2026
EPSS
0.024
83.3th percentile
Discovered by
Vendor
Vendor advisory field
Published
Jan 13, 2026
Assigned by fortinet

Description

A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets

Weakness: CWE-122

Affected products

Vendor Product Category Matched by
Fortinet FortiOS Firewall / NGFW cna-assigner
Fortinet FortiSwitch Routing & Switching cna-assigner
Vendor-reported products (3)
  • Fortinet · FortiSwitchManager
  • Fortinet · FortiOS
  • Siemens · RUGGEDCOM APE1808

Credit

Internally discovered and reported by Gwendal Guégniaud of Fortinet Product Security Team.

Vendor remediation

Upgrade to FortiSwitchManager version 7.2.7 or above Upgrade to FortiSwitchManager version 7.0.6 or above Fortinet remediated this issue in FortiSASE version 25.2.c and hence customers do not need to perform any action. Fortinet remediated this issue in FortiSASE version 25.1.b and hence customers do not need to perform any action. Upgrade to upcoming FortiOS version 8.0.0 or above Upgrade to FortiOS version 7.6.4 or above Upgrade to FortiOS version 7.4.9 or above Upgrade to FortiOS version 7.2.12 or above Upgrade to FortiOS version 7.0.18 or above

Something wrong here?