CVE-2025-25249: Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2026-09-09. EPSS: 3.8% chance of exploitation in the next 30 days.
A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets
Affected products
- Fortinet FortiOS: from 6.4.0, before 7.0.18 (fixed in 7.0.18); from 7.2.0, before 7.2.12 (fixed in 7.2.12); from 7.4.0, before 7.4.9 (fixed in 7.4.9); from 7.6.0, before 7.6.4 (fixed in 7.6.4)
- Fortinet Fortisase: version 25.1.39 only; version 25.1.51 only
- Fortinet Fortiswitchmanager: from 7.0.0, before 7.0.6 (fixed in 7.0.6); from 7.2.0, before 7.2.7 (fixed in 7.2.7)
- Siemens Ruggedcom APE1808 Firmware: affected versions not specified
Published 2026-01-13. Last modified 2026-10-07.