SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2025-32756

Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability

KEVCRITICAL 9.8EPSS 29.8%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 4 June 2025). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiCamera 1.1 all versions, FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail 7.0.0 through 7.0.8, FortiNDR 7.6.0, FortiNDR 7.4.0 through 7.4.7, FortiNDR 7.2.0 through 7.2.4, FortiNDR 7.0.0 through 7.0.6, FortiRecorder 7.2.0 through 7.2.3, FortiRecorder 7.0.0 through 7.0.5, FortiRecorder 6.4.0 through 6.4.5, FortiVoice 7.2.0, FortiVoice 7.0.0 through 7.0.6, FortiVoice 6.4.0 through 6.4.10 allows a remote unauthenticated attacker to execute arbitrary code or commands via sending HTTP requests with specially crafted hash cookie.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
29.81% probability · 98th percentile
CISA KEV
Listed 14 May 2025 · due 4 June 2025
Weakness
CWE-121, CWE-787
Affected
fortinet/fortimail · fortinet/fortindr · fortinet/fortirecorder · fortinet/fortivoice · fortinet/forticamera firmware
Source
psirt@fortinet.com

CISA notes

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. https://fortiguard.fortinet.com/psirt/FG-IR-25-254 ; https://nvd.nist.gov/vuln/detail/CVE-2025-32756

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.