THREAT OPS › CVEs › CVE-2025-25249
CVE-2025-25249 — Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets.
Vulnerability details
- Affected productsMultiple Products
- KEV remediation due2026-09-12
Related reporting
- Fortinet security advisory (AV26-023) - Update 1cccs_ca
- CISA Adds Four Known Exploited Vulnerabilities to Catalogcisa_advisories
- [NVD] CVE-2025-25249 (HIGH 8.1) — A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 alnvd
- [CISA KEV] CVE-2025-25249 — Fortinet Multiple Products: Fortinet Multiple Products Heap-based Buffer Overflow Vulnerabilitycisa_kev
- CVE-2025-25249 Exploitation Delivers PivotC2, a FortiGate Post-Exploitation RATsocradar_blog