CVE-2025-54820

A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiManager 7.4.0 through 7.4.2, FortiManager 7.2.0 through 7.2.10, FortiManager 6.4 all versions may allow a remote unauthenticated attacker to execute unauthorized commands via crafted requests, if the service is enabled. The success of the attack depends on the ability to bypass the stack protection mechanisms.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*

History

12 Mar 2026, 21:17

Type Values Removed Values Added
First Time Fortinet fortimanager
Fortinet
Summary
  • (es) Una vulnerabilidad de desbordamiento de búfer basado en pila [CWE-121] vulnerabilidad en Fortinet FortiManager 7.4.0 hasta 7.4.2, FortiManager 7.2.0 hasta 7.2.10, FortiManager 6.4 todas las versiones puede permitir a un atacante remoto no autenticado ejecutar comandos no autorizados a través de solicitudes manipuladas, si el servicio está habilitado. El éxito del ataque depende de la capacidad para eludir los mecanismos de protección de pila.
References () https://fortiguard.fortinet.com/psirt/FG-IR-26-098 - () https://fortiguard.fortinet.com/psirt/FG-IR-26-098 - Vendor Advisory
CPE cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*
CWE CWE-787

10 Mar 2026, 18:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-10 18:17

Updated : 2026-03-12 21:17


NVD link : CVE-2025-54820

Mitre link : CVE-2025-54820

CVE.ORG link : CVE-2025-54820


JSON object : View

Products Affected

fortinet

  • fortimanager
CWE
CWE-121

Stack-based Buffer Overflow

CWE-787

Out-of-bounds Write