CVE-2025-48839
An Out-of-bounds Write vulnerability [CWE-787] in FortiADC 8.0.0, 7.6.0 through 7.6.2, 7.4.0 through 7.4.7, 7.2 all versions, 7.1 all versions, 7.0 all versions, 6.2 all versions may allow an authenti
Severity
Medium 6.3
CVSS 3.1
Exploited
Not listed
EPSS
0.004
28.5th percentile
Discovered by
Not disclosed
Published
Nov 18, 2025
Assigned by fortinet
Description
An Out-of-bounds Write vulnerability [CWE-787] in FortiADC 8.0.0, 7.6.0 through 7.6.2, 7.4.0 through 7.4.7, 7.2 all versions, 7.1 all versions, 7.0 all versions, 6.2 all versions may allow an authenticated attacker to execute arbitrary code via specially crafted HTTP requests.
Weakness: CWE-787
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiADC | Web & Application Security | cna-assigner |
Vendor-reported affected versions (1)
- Fortinet · FortiADC
Vendor remediation
Upgrade to FortiADC version 8.0.1 or above Upgrade to FortiADC version 7.6.3 or above Upgrade to FortiADC version 7.4.8 or above