A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow an authenticated remote attacker to return a portion of device memory in the redirect response via submitting a specially crafted request.
References
| Link | Resource |
|---|---|
| https://fortiguard.fortinet.com/psirt/#5944 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
16 Jul 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow an authenticated remote attacker to return a portion of device memory in the redirect response via submitting a specially crafted request. |
15 Jul 2026, 18:32
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:* cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* |
|
| First Time |
Fortinet
Fortinet fortiproxy Fortinet fortios |
|
| References | () https://fortiguard.fortinet.com/psirt/#5944 - Vendor Advisory |
14 Jul 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-14 16:16
Updated : 2026-07-16 15:16
NVD link : CVE-2025-43892
Mitre link : CVE-2025-43892
CVE.ORG link : CVE-2025-43892
JSON object : View
Products Affected
fortinet
- fortios
- fortiproxy
CWE
CWE-126
Buffer Over-read
