CVE-2025-25249

EUVD-2026-2223
A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.1 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
fortinetfortios
6.4.0 ≤
𝑥
< 6.4.17
fortinetfortios
7.0.0 ≤
𝑥
< 7.0.18
fortinetfortios
7.2.0 ≤
𝑥
< 7.2.12
fortinetfortios
7.4.0 ≤
𝑥
< 7.4.9
fortinetfortios
7.6.0 ≤
𝑥
< 7.6.4
fortinetfortiswitchmanager
7.0.0 ≤
𝑥
< 7.0.6
fortinetfortiswitchmanager
7.2.0 ≤
𝑥
< 7.2.7
fortinetfortisase
25.1.39
fortinetfortisase
25.1.51
𝑥
= Vulnerable software versions