{
    "id": "CVE-2025-25249",
    "published": "2026-01-13 17:15:56",
    "last_modified": "2026-09-10 12:47:59",
    "cvss_score": "8.1",
    "cvss_severity": "HIGH",
    "cvss_version": "3.1",
    "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "cwe": "CWE-122",
    "description": "A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets",
    "epss_score": "0.03859",
    "epss_percentile": "0.89802",
    "kev": 1,
    "kev_due": "2026-09-12",
    "has_exploit": 0,
    "updated_at": "2026-09-27 18:17:49",
    "priority": {
        "rank": 1,
        "label": "Patch first",
        "why": "On CISA KEV — known exploited in the wild, due 2026-09-12."
    },
    "products": [
        {
            "vendor": "fortinet",
            "product": "fortios"
        },
        {
            "vendor": "fortinet",
            "product": "fortisase"
        },
        {
            "vendor": "fortinet",
            "product": "fortiswitchmanager"
        },
        {
            "vendor": "siemens",
            "product": "ruggedcom_ape1808"
        },
        {
            "vendor": "siemens",
            "product": "ruggedcom_ape1808_firmware"
        }
    ],
    "kev_detail": {
        "cve_id": "CVE-2025-25249",
        "date_added": "2026-09-09",
        "due_date": "2026-09-12",
        "vendor": "Fortinet",
        "product": "Multiple Products",
        "name": "Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability",
        "ransomware": 0
    },
    "exploits": [],
    "refs_list": [
        "https://fortiguard.fortinet.com/psirt/FG-IR-25-084",
        "https://cert-portal.siemens.com/productcert/html/ssa-864900.html",
        "https://socradar.io/blog/cve-2025-25249-pivotc2-fortigate-rat/",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-25249"
    ]
}