CVE-2025-32766

Severity
6.7MEDIUM
EPSS
0.0%
top 95.52%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 12

Description

A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiWeb CLI version 7.6.0 through 7.6.3 and before 7.4.8 allows a privileged attacker to execute arbitrary code or commands via crafted CLI commands

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 0.5 | Impact: 5.9

Affected Packages2 packages

NVDfortinet/fortiweb7.4.17.4.9+1
CVEListV5fortinet/fortiweb7.6.07.6.3+1

🔴Vulnerability Details

2
GHSA
GHSA-5j9x-j6c3-rwxp: A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiWeb CLI version 72025-08-12
CVEList
CVE-2025-32766: A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiWeb CLI version 72025-08-12

📋Vendor Advisories

1
Fortinet
A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiWeb CLI version 7.6.0 through 7.6.3 and before 7...2025-08-12
CVE-2025-32766 (MEDIUM CVSS 6.7) | A stack-based buffer overflow vulne | cvebase.io