CVE-2025-32766
published 2025-08-12CVE-2025-32766: A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiWeb CLI version 7.6.0 through 7.6.3 and before 7.4.8 allows a privileged attacker to…
PriorityP336medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.13%
2.7th percentile
A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiWeb CLI version 7.6.0 through 7.6.3 and before 7.4.8 allows a privileged attacker to execute arbitrary code or commands via crafted CLI commands
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinet | — | — |
| fortinet | fortiweb | — | — |
| fortinet | fortiweb | >= 7.4.1 < 7.4.9 | 7.4.9 |
| fortinet | fortiweb | 7.4.1 – 7.4.8 | — |
| fortinet | fortiweb | >= 7.6.0 < 7.6.4 | 7.6.4 |
| fortinet | fortiweb | 7.6.0 – 7.6.3 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5j9x-j6c3-rwxp: A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiWeb CLI version 7
ghsa_unreviewed·2025-08-12
CVE-2025-32766 [MEDIUM] CWE-121 GHSA-5j9x-j6c3-rwxp: A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiWeb CLI version 7
A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiWeb CLI version 7.6.0 through 7.6.3 and before 7.4.8 allows a privileged attacker to execute arbitrary code or commands via crafted CLI commands
Fortinet
A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiWeb CLI version 7.6.0 through 7.6.3 and before 7...
vendor_fortinet·2025-08-12·CVSS 6.4
CVE-2025-32766 [MEDIUM] CWE-121 A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiWeb CLI version 7.6.0 through 7.6.3 and before 7...
FG-IR-25-383: A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiWeb CLI version 7.6.0 through 7.6.3 and before 7...
A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiWeb CLI version 7.6.0 through 7.6.3 and before 7.4.8 allows a privileged attacker to execute arbitrary code or commands via crafted CLI commands
CVEs: CVE-2025-32766
CWEs: CWE-121
CVSS: 6.4 (medium)
Affected products: FortiWeb, Fortinet
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-08-12
Published