CVE-2025-25249

A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4.0 through 6.4.16, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:fortinet:fortiswitchmanager:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortiswitchmanager:*:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:a:fortinet:fortisase:25.1.39:*:*:*:-:*:*:*
cpe:2.3:a:fortinet:fortisase:25.1.51:*:*:*:-:*:*:*

History

16 Jan 2026, 09:16

Type Values Removed Values Added
Summary (en) A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4.0 through 6.4.16, FortiSASE 25.2.b, FortiSASE 25.1.a.2, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets (en) A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4.0 through 6.4.16, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets

14 Jan 2026, 21:33

Type Values Removed Values Added
CPE cpe:2.3:a:fortinet:fortiswitchmanager:*:*:*:*:*:*:*:*
cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisase:25.1.39:*:*:*:-:*:*:*
cpe:2.3:a:fortinet:fortisase:25.1.51:*:*:*:-:*:*:*
References () https://fortiguard.fortinet.com/psirt/FG-IR-25-084 - () https://fortiguard.fortinet.com/psirt/FG-IR-25-084 - Vendor Advisory
CWE CWE-787
First Time Fortinet
Fortinet fortios
Fortinet fortisase
Fortinet fortiswitchmanager

13 Jan 2026, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-13 17:15

Updated : 2026-01-16 09:16


NVD link : CVE-2025-25249

Mitre link : CVE-2025-25249

CVE.ORG link : CVE-2025-25249


JSON object : View

Products Affected

fortinet

  • fortisase
  • fortiswitchmanager
  • fortios
CWE
CWE-122

Heap-based Buffer Overflow

CWE-787

Out-of-bounds Write