← Back to CVE List
CVE-2025-25249NVD
Vulnerability Summary
A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets
CVSS v3.1 Base Metrics — Score 8.1 (HIGH)
Attack VectorNetwork
Attack ComplexityHigh
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
Affected & Patched Versions
- Fortinet Fortios >= 6.4.0 and < 7.0.18
- Fortinet Fortios >= 7.2.0 and < 7.2.12
- Fortinet Fortios >= 7.4.0 and < 7.4.9
- Fortinet Fortios >= 7.6.0 and < 7.6.4
- Fortinet Fortiswitchmanager >= 7.0.0 and < 7.0.6
- Fortinet Fortiswitchmanager >= 7.2.0 and < 7.2.7
- Fortinet Fortisase
- Siemens Ruggedcom Ape1808 Firmware
- Fortinet Fortios 7.0.18
- Fortinet Fortios 7.2.12
- Fortinet Fortios 7.4.9
- Fortinet Fortios 7.6.4
- Fortinet Fortiswitchmanager 7.0.6
- Fortinet Fortiswitchmanager 7.2.7