CVE-2025-25249
published 2026-01-13CVE-2025-25249: A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0…
PriorityP357critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.75%
50.5th percentile
A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinet | — | — |
| fortinet | fortios | — | — |
| fortinet | fortios | >= 6.4.0 < 6.4.17 | 6.4.17 |
| fortinet | fortios | >= 7.0.0 < 7.0.18 | 7.0.18 |
| fortinet | fortios | >= 7.2.0 < 7.2.12 | 7.2.12 |
| fortinet | fortios | 7.2.4 – 7.2.11 | — |
| fortinet | fortios | >= 7.4.0 < 7.4.9 | 7.4.9 |
| fortinet | fortios | 7.4.0 – 7.4.7 | — |
| fortinet | fortios | >= 7.6.0 < 7.6.4 | 7.6.4 |
| fortinet | fortios | 7.6.0 – 7.6.2 | — |
| fortinet | fortisase | — | — |
| fortinet | fortisase | — | — |
| fortinet | fortisase | — | — |
| fortinet | fortiswitchmanager | — | — |
| fortinet | fortiswitchmanager | >= 7.0.0 < 7.0.6 | 7.0.6 |
| fortinet | fortiswitchmanager | >= 7.2.0 < 7.2.7 | 7.2.7 |
| fortinet | fortiswitchmanager | 7.2.2 – 7.2.5 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
Heap-based buffer overflow in cw_acd daemon
vendor_fortinet·2026-01-13·CVSS 8.1
CVE-2025-25249 [HIGH] CWE-122 Heap-based buffer overflow in cw_acd daemon
FG-IR-25-084: Heap-based buffer overflow in cw_acd daemon
A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets
CVEs: CVE-2025-25249
CWEs: CWE-122, CWE-787
CVSS: 8.1 (high)
Affected products: FortiOS, FortiSase, FortiSwitchManager, FortiSwitchmanager, Fortinet
GHSA
GHSA-mj8x-m8f5-x4w8: A heap-based buffer overflow vulnerability in Fortinet FortiOS 7
ghsa_unreviewed·2026-01-13
CVE-2025-25249 [HIGH] CWE-122 GHSA-mj8x-m8f5-x4w8: A heap-based buffer overflow vulnerability in Fortinet FortiOS 7
A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4.0 through 6.4.16, FortiSASE 25.2.b, FortiSASE 25.1.a.2, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets
No detection rules found.
No public exploits indexed.
2026-01-13
Published