CVE-2025-25249
HIGHA heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets
Published: 1/13/2026Modified: 9/10/2026
Related Intelligence (0)
No articles currently reference this CVE.
References (4)
https://fortiguard.fortinet.com/psirt/FG-IR-25-084Vendor AdvisoryMitigationhttps://cert-portal.siemens.com/productcert/html/ssa-864900.htmlThird Party Advisoryhttps://socradar.io/blog/cve-2025-25249-pivotc2-fortigate-rat/ExploitThird Party Advisoryhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-25249US Government Resource