CVE-2025-22258: Fortinet FortiOS

High severity, CVSS 7.2. EPSS: 0.6% chance of exploitation in the next 30 days.

A heap-based buffer overflow in Fortinet FortiSRA 1.5.0, 1.4.0 through 1.4.2, FortiPAM 1.5.0, 1.4.0 through 1.4.2, 1.3.0 through 1.3.1, 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiProxy 7.6.0 through 7.6.1, 7.4.0 through 7.4.7, FortiOS 7.6.0 through 7.6.2, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.2 through 7.0.16, FortiSwitchManager 7.2.1 through 7.2.5 allows attackers to escalate their privilege via specially crafted http requests.

Affected products

  • Fortinet FortiOS: from 7.0.2, before 7.0.17 (fixed in 7.0.17); from 7.2.0, before 7.2.11 (fixed in 7.2.11); from 7.4.0, before 7.4.7 (fixed in 7.4.7); from 7.6.0, before 7.6.3 (fixed in 7.6.3)
  • Fortinet Fortipam: from 1.0.0, before 1.4.3 (fixed in 1.4.3); version 1.5.0 only
  • Fortinet FortiProxy: from 7.4.0, before 7.4.8 (fixed in 7.4.8); from 7.6.0, before 7.6.2 (fixed in 7.6.2)
  • Fortinet Fortisra: from 1.4.0, before 1.4.3 (fixed in 1.4.3); version 1.5.0 only
  • Fortinet Fortiswitchmanager: from 7.2.1, before 7.2.6 (fixed in 7.2.6)

Published 2025-10-14. Last modified 2026-06-17.