← Browse

CVE-2025-25249

Act now ● On CISA KEV — actively exploited

Actively exploited — on the CISA KEV list.

CVSS base
8.1 HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS — probability of exploitation (30 days)
2.4%
83.3th percentile
CISA KEV
Listed
Added 2026-09-09 · patch by 2026-09-12
Weakness / dates
CWE-787
Published 2026-01-13 · modified 2026-09-10

Description

A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets

Affected

fortinet siemens

References

Official: NVD · CVE.org