A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets
References
| Link | Resource |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-25-084 | Vendor Advisory Mitigation |
| https://cert-portal.siemens.com/productcert/html/ssa-864900.html | Third Party Advisory |
| https://socradar.io/blog/cve-2025-25249-pivotc2-fortigate-rat/ | Exploit Third Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-25249 | US Government Resource |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
| AND |
|
History
No history.
Information
Published : 2026-01-13 17:15
Updated : 2026-09-10 12:47
NVD link : CVE-2025-25249
Mitre link : CVE-2025-25249
CVE.ORG link : CVE-2025-25249
JSON object : View
Products Affected
siemens
- ruggedcom_ape1808_firmware
- ruggedcom_ape1808
fortinet
- fortios
- fortisase
- fortiswitchmanager
