Severity
9.8CRITICAL
EPSS
0.0%
top 97.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 13

Description

A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.2 | Impact: 5.9

Affected Packages5 packages

NVDfortinet/fortios6.4.06.4.17+4
CVEListV5fortinet/fortios7.6.07.6.2+2
NVDfortinet/fortiswitchmanager7.0.07.0.6+1
CVEListV5fortinet/fortiswitchmanager7.2.27.2.5
NVDfortinet/fortisase25.1.39, 25.1.51+1

🔴Vulnerability Details

2
CVEList
CVE-2025-25249: A heap-based buffer overflow vulnerability in Fortinet FortiOS 72026-01-13
GHSA
GHSA-mj8x-m8f5-x4w8: A heap-based buffer overflow vulnerability in Fortinet FortiOS 72026-01-13

📋Vendor Advisories

1
Fortinet
Heap-based buffer overflow in cw_acd daemon2026-01-13

🕵️Threat Intelligence

1
Wiz
CVE-2025-25249 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2025-25249 (CRITICAL CVSS 9.8) | A heap-based buffer overflow vulner | cvebase.io