A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4.0 through 6.4.16, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets
References
| Link | Resource |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-25-084 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
History
16 Jan 2026, 09:16
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4.0 through 6.4.16, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets |
14 Jan 2026, 21:33
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:fortinet:fortiswitchmanager:*:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortisase:25.1.39:*:*:*:-:*:*:* cpe:2.3:a:fortinet:fortisase:25.1.51:*:*:*:-:*:*:* |
|
| References | () https://fortiguard.fortinet.com/psirt/FG-IR-25-084 - Vendor Advisory | |
| CWE | CWE-787 | |
| First Time |
Fortinet
Fortinet fortios Fortinet fortisase Fortinet fortiswitchmanager |
13 Jan 2026, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-13 17:15
Updated : 2026-01-16 09:16
NVD link : CVE-2025-25249
Mitre link : CVE-2025-25249
CVE.ORG link : CVE-2025-25249
JSON object : View
Products Affected
fortinet
- fortisase
- fortiswitchmanager
- fortios
