cbcvebase.
CVE-2025-32756
published 2025-05-13

CVE-2025-32756: A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiCamera 1.1…

PriorityP1100critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2025-06-04
Exploited in the wild
EPSS
31.42%
98.1th percentile
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiCamera 1.1 all versions, FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail 7.0.0 through 7.0.8, FortiNDR 7.6.0, FortiNDR 7.4.0 through 7.4.7, FortiNDR 7.2.0 through 7.2.4, FortiNDR 7.0.0 through 7.0.6, FortiRecorder 7.2.0 through 7.2.3, FortiRecorder 7.0.0 through 7.0.5, FortiRecorder 6.4.0 through 6.4.5, FortiVoice 7.2.0, FortiVoice 7.0.0 through 7.0.6, FortiVoice 6.4.0 through 6.4.10 allows a remote unauthenticated attacker to execute arbitrary code or commands via sending HTTP requests with specially crafted hash cookie.

Affected

48 ranges· showing 25
VendorProductVersion rangeFixed in
fortinetforticamera
fortinetforticamera
fortinetforticamera1.1.0 – 1.1.5
fortinetforticamera2.1.0 – 2.1.3
fortinetforticamera_firmware1.1.0 – 1.1.5
fortinetforticamera_firmware2.0.0 – 2.1.3
fortinetforticamerafirmware
fortinetfortimail
fortinetfortimail>= 7.0.0 < 7.0.97.0.9
fortinetfortimail7.0.0 – 7.0.8
fortinetfortimail>= 7.2.0 < 7.2.87.2.8
fortinetfortimail7.2.0 – 7.2.7
fortinetfortimail>= 7.4.0 < 7.4.57.4.5
fortinetfortimail7.4.0 – 7.4.4
fortinetfortimail>= 7.6.0 < 7.6.37.6.3
fortinetfortimail7.6.0 – 7.6.2
fortinetfortindr
fortinetfortindr
fortinetfortindr
fortinetfortindr
fortinetfortindr
fortinetfortindr
fortinetfortindr
fortinetfortindr
fortinetfortindr

Detection & IOCsextracted from sources · hover to see the quote

ip198.105.127.124
ip43.228.217.173
ip43.228.217.82
ip156.236.76.90
ip218.187.69.244
ip218.187.69.59
commanddiag debug application fcgi
cookiespecially crafted hash cookie
  • Look for 'fcgi debugging' toggled on (non-default) on Fortinet devices — this is an attacker-set indicator used to log credentials from the system or SSH login attempts.
  • Hunt for evidence of system crashlogs deletion on Fortinet devices, used by threat actors to cover their tracks post-exploitation.
  • Detect newly added cron jobs on Fortinet devices — threat actors deployed cron jobs designed to harvest credentials post-exploitation.
  • Monitor for unexpected network scanning scripts dropped on Fortinet devices, indicating post-exploitation lateral movement activity.
  • Inspect inbound HTTP requests to Fortinet administrative interfaces for malformed or oversized hash cookie values as the exploit vector.
  • ·Disabling the HTTP/HTTPS administrative interface on vulnerable Fortinet devices is the recommended mitigation for those unable to immediately patch.
  • ·The 'fcgi debugging' feature is NOT enabled by default; its presence on a device is a strong indicator of compromise.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.