CVE-2025-25249

EUVD-2026-2223
A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.1 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
fortinetCNA
7.4 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:W/RC:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 1%
Affected Products (NVD)
VendorProductVersion
fortinetfortios
6.4.0 ≤
𝑥
< 6.4.17
fortinetfortios
7.0.0 ≤
𝑥
< 7.0.18
fortinetfortios
7.2.0 ≤
𝑥
< 7.2.12
fortinetfortios
7.4.0 ≤
𝑥
< 7.4.9
fortinetfortios
7.6.0 ≤
𝑥
< 7.6.4
fortinetfortiswitchmanager
7.0.0 ≤
𝑥
< 7.0.6
fortinetfortiswitchmanager
7.2.0 ≤
𝑥
< 7.2.7
fortinetfortisase
25.1.39
fortinetfortisase
25.1.51
𝑥
= Vulnerable software versions