CVE-2025-48839
published 2025-11-18CVE-2025-48839: An Out-of-bounds Write vulnerability [CWE-787] in FortiADC 8.0.0, 7.6.0 through 7.6.2, 7.4.0 through 7.4.7, 7.2 all versions, 7.1 all versions, 7.0 all…
PriorityP342medium6.6CVSS 3.1
AVNACHPRHUINSUCHIHAH
EPSS
0.33%
24.7th percentile
An Out-of-bounds Write vulnerability [CWE-787] in FortiADC 8.0.0, 7.6.0 through 7.6.2, 7.4.0 through 7.4.7, 7.2 all versions, 7.1 all versions, 7.0 all versions, 6.2 all versions may allow an authenticated attacker to execute arbitrary code via specially crafted HTTP requests.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortiadc | — | — |
| fortinet | fortiadc | — | — |
| fortinet | fortiadc | >= 6.2.0 < 7.4.8 | 7.4.8 |
| fortinet | fortiadc | 6.2.0 – 6.2.6 | — |
| fortinet | fortiadc | 7.0.0 – 7.0.6 | — |
| fortinet | fortiadc | 7.1.0 – 7.1.5 | — |
| fortinet | fortiadc | 7.2.0 – 7.2.8 | — |
| fortinet | fortiadc | 7.4.0 – 7.4.7 | — |
| fortinet | fortiadc | >= 7.6.0 < 7.6.3 | 7.6.3 |
| fortinet | fortiadc | 7.6.0 – 7.6.2 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-25x7-2m3g-jhfw: An Out-of-bounds Write vulnerability [CWE-787] in FortiADC 8
ghsa_unreviewed·2025-11-18
CVE-2025-48839 [MEDIUM] CWE-787 GHSA-25x7-2m3g-jhfw: An Out-of-bounds Write vulnerability [CWE-787] in FortiADC 8
An Out-of-bounds Write vulnerability [CWE-787] in FortiADC 8.0.0, 7.6.0 through 7.6.2, 7.4.0 through 7.4.7, 7.2 all versions, 7.1 all versions, 7.0 all versions, 6.2 all versions may allow an authenticated attacker to execute arbitrary code via specially crafted HTTP requests.
Fortinet
An Out-of-bounds Write vulnerability [CWE-787] in FortiADC 8.0.0, 7.6.0 through 7.6.2, 7.4.0 through 7.4.7, 7.2 all vers...
vendor_fortinet·2025-11-18·CVSS 6.6
CVE-2025-48839 [MEDIUM] CWE-787 An Out-of-bounds Write vulnerability [CWE-787] in FortiADC 8.0.0, 7.6.0 through 7.6.2, 7.4.0 through 7.4.7, 7.2 all vers...
FG-IR-25-225: An Out-of-bounds Write vulnerability [CWE-787] in FortiADC 8.0.0, 7.6.0 through 7.6.2, 7.4.0 through 7.4.7, 7.2 all vers...
An Out-of-bounds Write vulnerability [CWE-787] in FortiADC 8.0.0, 7.6.0 through 7.6.2, 7.4.0 through 7.4.7, 7.2 all versions, 7.1 all versions, 7.0 all versions, 6.2 all versions may allow an authenticated attacker to execute arbitrary code via specially crafted HTTP requests.
CVEs: CVE-2025-48839
CWEs: CWE-787
CVSS: 6.6 (medium)
Affected products: FortiADC
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-11-18
Published