CVE-2025-54820

A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiManager 7.4.0 through 7.4.2, FortiManager 7.2.0 through 7.2.10, FortiManager 6.4 all versions may allow a remote un

Severity
High 7
CVSS 3.1
Exploited
Not listed
EPSS
0.009
57.3th percentile
Discovered by
Third party
Vendor advisory field
Published
Mar 10, 2026
Assigned by fortinet

Description

A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiManager 7.4.0 through 7.4.2, FortiManager 7.2.0 through 7.2.10, FortiManager 6.4 all versions may allow a remote unauthenticated attacker to execute unauthorized commands via crafted requests, if the service is enabled. The success of the attack depends on the ability to bypass the stack protection mechanisms.

Weakness: CWE-121

Affected products

Vendor Product Category Matched by
Fortinet FortiManager Network & Security Management cna-assigner
Vendor-reported products (1)
  • Fortinet · FortiManager

Credit

Fortinet is pleased to thank catalpa from Dbappsecurity Co., Ltd. for reporting this vulnerability under responsible disclosure

Vendor remediation

Upgrade to FortiManager version 7.6.0 or above Upgrade to FortiManager version 7.4.3 or above Upgrade to FortiManager version 7.2.11 or above Upgrade to upcoming FortiManager version 6.4.16 or above

Something wrong here?