CVE-2025-32756
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiCamera 1.1 all versions, FortiMail 7.6.0 through 7.6
Description
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiCamera 1.1 all versions, FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail 7.0.0 through 7.0.8, FortiNDR 7.6.0, FortiNDR 7.4.0 through 7.4.7, FortiNDR 7.2.0 through 7.2.4, FortiNDR 7.0.0 through 7.0.6, FortiRecorder 7.2.0 through 7.2.3, FortiRecorder 7.0.0 through 7.0.5, FortiRecorder 6.4.0 through 6.4.5, FortiVoice 7.2.0, FortiVoice 7.0.0 through 7.0.6, FortiVoice 6.4.0 through 6.4.10 allows a remote unauthenticated attacker to execute arbitrary code or commands via sending HTTP requests with specially crafted hash cookie.
Weakness: CWE-121
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiCamera | Other Products | cna-assigner |
| Fortinet | FortiMail | Email Security | cna-assigner |
| Fortinet | FortiNDR | Threat Detection & Sandbox | cna-assigner |
| Fortinet | FortiRecorder | Other Products | cna-assigner |
| Fortinet | FortiVoice | Other Products | cna-assigner |
Vendor-reported products (5)
- Fortinet · FortiNDR
- Fortinet · FortiCamera
- Fortinet · FortiRecorder
- Fortinet · FortiVoice
- Fortinet · FortiMail
Credit
Discovered by Théo Leleu and David Maciejak of Fortinet Product Security Team based on threat activity.
Vendor remediation
Upgrade to FortiNDR version 7.6.1 or above Upgrade to FortiNDR version 7.4.8 or above Upgrade to FortiNDR version 7.2.5 or above Upgrade to FortiNDR version 7.0.7 or above Upgrade to FortiCamera version 2.1.4 or above Upgrade to FortiRecorder version 7.2.4 or above Upgrade to FortiRecorder version 7.0.6 or above Upgrade to FortiRecorder version 6.4.6 or above Upgrade to FortiVoice version 7.2.1 or above Upgrade to FortiVoice version 7.0.7 or above Upgrade to FortiVoice version 6.4.11 or above Upgrade to FortiMail version 7.6.3 or above Upgrade to FortiMail version 7.4.5 or above Upgrade to FortiMail version 7.2.8 or above Upgrade to FortiMail version 7.0.9 or above