CVE-2025-25249: Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2026-09-09. EPSS: 3.8% chance of exploitation in the next 30 days.

A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets

Affected products

  • Fortinet FortiOS: from 6.4.0, before 7.0.18 (fixed in 7.0.18); from 7.2.0, before 7.2.12 (fixed in 7.2.12); from 7.4.0, before 7.4.9 (fixed in 7.4.9); from 7.6.0, before 7.6.4 (fixed in 7.6.4)
  • Fortinet Fortisase: version 25.1.39 only; version 25.1.51 only
  • Fortinet Fortiswitchmanager: from 7.0.0, before 7.0.6 (fixed in 7.0.6); from 7.2.0, before 7.2.7 (fixed in 7.2.7)
  • Siemens Ruggedcom APE1808 Firmware: affected versions not specified

Published 2026-01-13. Last modified 2026-10-07.