CyberICT

CVE-2025-25249

Fortinet · Published January 13, 2026

CVSS v3.1

CRITICAL
Patch availableGet patch

Description

A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets

Affected Products

  • Fortios < 6.4.17
  • Fortios < 7.0.18
  • Fortios < 7.2.12
  • Fortios < 7.4.9

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H