cbcvebase.
CVE-2025-54820
published 2026-03-10

CVE-2025-54820: A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiManager 7.4.0 through 7.4.2, FortiManager 7.2.0 through 7.2.10…

PriorityP264high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
0.87%
55.1th percentile
A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiManager 7.4.0 through 7.4.2, FortiManager 7.2.0 through 7.2.10, FortiManager 6.4 all versions may allow a remote unauthenticated attacker to execute unauthorized commands via crafted requests, if the service is enabled. The success of the attack depends on the ability to bypass the stack protection mechanisms.

Affected

7 ranges
VendorProductVersion rangeFixed in
fortinetfortimanager
fortinetfortimanager>= 6.4.0 < 7.2.117.2.11
fortinetfortimanager6.4.0 – 6.4.15
fortinetfortimanager7.2.0 – 7.2.10
fortinetfortimanager>= 7.4.0 < 7.4.37.4.3
fortinetfortimanager7.4.0 – 7.4.2
fortinetfortinet

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability is triggered via crafted requests to the 'fgtupdates' service on FortiManager. Detection should focus on anomalous or malformed requests targeting this service.
  • The advisory title 'Buffer overflow via fgtupdates service' identifies 'fgtupdates' as the specific vulnerable service. Monitor for unexpected activity or connections to/from this service on FortiManager instances.
  • Exploitation requires bypassing stack protection mechanisms (e.g., stack canaries, ASLR). Look for crash/core dump artifacts or unexpected process termination of the fgtupdates service as indicators of exploitation attempts.
  • ·The vulnerability only applies if the fgtupdates service is enabled on the FortiManager instance. Disabling the service removes the attack surface.
  • ·Affected versions are FortiManager 7.4.0–7.4.2, 7.2.0–7.2.10, and 6.4 all versions. FortiManager 7.4.3+ and 7.2.11+ are not listed as affected.
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.