CVE-2025-46776
published 2025-11-18CVE-2025-46776: A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiExtender 7.6.0 through 7.6.1, FortiExtender 7.4.0…
PriorityP343high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.14%
3.7th percentile
A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiExtender 7.6.0 through 7.6.1, FortiExtender 7.4.0 through 7.4.6, FortiExtender 7.2 all versions, FortiExtender 7.0 all versions may allow an authenticated user to execute arbitrary code or commands via crafted CLI commands.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortiextender | — | — |
| fortinet | fortiextender | 7.0.0 – 7.0.5 | — |
| fortinet | fortiextender | 7.2.0 – 7.2.5 | — |
| fortinet | fortiextender | 7.4.0 – 7.4.6 | — |
| fortinet | fortiextender | 7.6.0 – 7.6.1 | — |
| fortinet | fortiextender_firmware | >= 7.0.0 < 7.4.8 | 7.4.8 |
| fortinet | fortiextender_firmware | >= 7.6.0 < 7.6.3 | 7.6.3 |
| fortinet | fortiextenderfirmware | — | — |
| fortinet | fortinet | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
Authenticated CLI Commands Buffer Overflow
vendor_fortinet·2025-11-18·CVSS 6.4
CVE-2025-46776 [MEDIUM] CWE-120 Authenticated CLI Commands Buffer Overflow
FG-IR-25-251: Authenticated CLI Commands Buffer Overflow
A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiExtender 7.6.0 through 7.6.1, FortiExtender 7.4.0 through 7.4.6, FortiExtender 7.2 all versions, FortiExtender 7.0 all versions may allow an authenticated user to execute arbitrary code or commands via crafted CLI commands.
CVEs: CVE-2025-46776
CWEs: CWE-120
CVSS: 6.4 (medium)
Affected products: FortiExtender, FortiExtenderfirmware, Fortinet
GHSA
GHSA-xhvc-jjj4-9gq2: A buffer copy without checking size of input ('classic buffer overflow') in Fortinet FortiExtender 7
ghsa_unreviewed·2025-11-18
CVE-2025-46776 [MEDIUM] CWE-120 GHSA-xhvc-jjj4-9gq2: A buffer copy without checking size of input ('classic buffer overflow') in Fortinet FortiExtender 7
A buffer copy without checking size of input ('classic buffer overflow') in Fortinet FortiExtender 7.6.0 through 7.6.1, FortiExtender 7.4.0 through 7.4.6, FortiExtender 7.2 all versions, FortiExtender 7.0 all versions may allow an authenticated user to execute arbitrary code or commands via crafted CLI commands.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-11-18
Published