CVE-2025-58903

An Unchecked Return Value vulnerability [CWE-252] in Fortinet FortiOS version 7.6.0 through 7.6.3 and before 7.4.8 API allows an authenticated user to cause a Null Pointer Dereference, crashing the h

Severity
Low 2.5
CVSS 3.1
Exploited
Not listed
EPSS
0.006
44.2th percentile
Discovered by
Not disclosed
Published
Oct 14, 2025
Assigned by fortinet

Description

An Unchecked Return Value vulnerability [CWE-252] in Fortinet FortiOS version 7.6.0 through 7.6.3 and before 7.4.8 API allows an authenticated user to cause a Null Pointer Dereference, crashing the http daemon via a specialy crafted request.

Weakness: CWE-252

Affected products

Vendor Product Category Matched by
Fortinet FortiOS Firewall / NGFW cna-assigner
Vendor-reported affected versions (2)
  • Fortinet · FortiOS
  • Siemens · RUGGEDCOM APE1808

Vendor remediation

Upgrade to upcoming FortiOS version 8.0.0 or above Upgrade to FortiOS version 7.6.4 or above Upgrade to FortiOS version 7.4.9 or above