CVE-2025-58903: Fortinet FortiOS

Medium severity, CVSS 4.9. EPSS: 0.6% chance of exploitation in the next 30 days.

An Unchecked Return Value vulnerability [CWE-252] in Fortinet FortiOS version 7.6.0 through 7.6.3 and before 7.4.8 API allows an authenticated user to cause a Null Pointer Dereference, crashing the http daemon via a specialy crafted request.

Affected products

  • Fortinet FortiOS: from 6.4.0, before 7.4.9 (fixed in 7.4.9); from 7.6.0, before 7.6.4 (fixed in 7.6.4)

Published 2025-10-14. Last modified 2026-10-08.