CVE-2025-25249

A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, F

Severity
High 7.4
CVSS 3.1
Remote · no auth what this means
Exploited
Yes — in CISA KEV
Added Sep 9, 2026
EPSS
0.039
89.9th percentile
Discovered by
Vendor
Vendor advisory field
Published
Jan 13, 2026
Assigned by fortinet

Description

A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets

Weakness: CWE-122

Affected products

Vendor Product Category Matched by
Fortinet FortiOS Check your version Firewall / NGFW cna-assigner
Fortinet FortiSwitch Routing & Switching cna-assigner
Vendor-reported products (3)
  • Fortinet · FortiSwitchManager
  • Fortinet · FortiOS
  • Siemens · RUGGEDCOM APE1808

Credit

Internally discovered and reported by Gwendal Guégniaud of Fortinet Product Security Team.

Vendor remediation

Upgrade to FortiSwitchManager version 7.2.7 or above Upgrade to FortiSwitchManager version 7.0.6 or above Fortinet remediated this issue in FortiSASE version 25.2.c and hence customers do not need to perform any action. Fortinet remediated this issue in FortiSASE version 25.1.b and hence customers do not need to perform any action. Upgrade to upcoming FortiOS version 8.0.0 or above Upgrade to FortiOS version 7.6.4 or above Upgrade to FortiOS version 7.4.9 or above Upgrade to FortiOS version 7.2.12 or above Upgrade to FortiOS version 7.0.18 or above

Something wrong here?