peter bassill · operator
$ cve CVE-2025-25249 JSON

CVE-2025-25249 KEV

8.1
HIGH · CVSS 3.1 · EPSS 3.9% (pctl 90)

Patch first

On CISA KEV — known exploited in the wild, due 2026-09-12.

Description

A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets

Scoring

CVSS8.1 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.86% — more likely to be exploited than 90% of all CVEs
WeaknessCWE-122
On CISA KEVyes — remediate by 2026-09-12
Public exploitnone known
Published2026-01-13
Last modified2026-09-10

CISA KEV

NameFortinet Multiple Products Heap-based Buffer Overflow Vulnerability
Added2026-09-09
Due2026-09-12
Vendor / productFortinet / Multiple Products
Ransomware usenone reported

Affected (5)

VendorProduct
fortinetfortios
fortinetfortisase
fortinetfortiswitchmanager
siemensruggedcom ape1808
siemensruggedcom ape1808 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD