CVE-2025-25249

CRITICAL

A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions...

Affects 3 products across 3 vendors.

BCS6.46
CVSS 3.19.8
EPSS0.7%
Percentile51th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-122: Heap-Based Buffer Overflow

Buffer overflow corrupting dynamically allocated heap memory, exploitable for arbitrary code execution.

CWE-787: Out-of-Bounds Write

Software writes data past buffer boundaries, corrupting memory and potentially enabling code execution.

Related Attack Patterns (CAPEC)
CAPEC-92 Forced Integer Overflow
via CWE-122

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A heap-based buffer overflow vulnerability in multiple versions of Fortinet FortiOS and FortiSwitchManager allows an attacker to execute unauthorized code or commands via specially crafted packets. This vulnerability has a CVSS score of 9.8, indicating a critical severity level. Immediate action is required to mitigate the risk of exploitation.

BSID: BS-2026-GLOBAL-247236-C • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2025-25249?
A heap-based buffer overflow vulnerability in multiple versions of Fortinet FortiOS and FortiSwitchManager allows an attacker to execute unauthorized code or commands via specially crafted packets. This vulnerability has a CVSS score of 9.8, indicating a critical severity level. Immediate action is required to mitigate the risk of exploitation.
What is the CVSS score for CVE-2025-25249?
CVE-2025-25249 has CVSS 9.8 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 0.7%.
Is CVE-2025-25249 actively exploited?
No confirmed active exploitation of CVE-2025-25249 as of 2026-05-30.
How do I remediate CVE-2025-25249?
Priority: IMMEDIATE. Advisory: https://fortiguard.fortinet.com/psirt/FG-IR-25-084 PSIRT: [email protected]
What systems are affected by CVE-2025-25249?
CVE-2025-25249 affects: Fortinet, Fortinet, Fortinet, Fujitsu-Siemens, Siemens.
What NERC-CIP standard applies to CVE-2025-25249?
NERC CIP CIP-007 CIP-007-R2: This vulnerability could allow an attacker to gain unauthorized access to critical systems, violating the requirement for secure access controls and the protection of critical cyber assets.
What IEC 62443 requirement maps to CVE-2025-25249?
IEC 62443 SR 7.6: The vulnerability poses a significant risk to the integrity and availability of the control system, which is a key requirement under IEC 62443-4-2 for secure system design and implementation.
Vulnerability Details
CVE IDCVE-2025-25249
BSIDBS-2026-GLOBAL-247236-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2026-01-13
Last Modified2026-02-23
ICS Relevance70%
Weakness (CWE)
Verticals
ICS-OT
Domains
NETWORK-INFRA
SourceNVD
Official Description

A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability can be exploited remotely without authentication, requiring only network access to the affected device. An attacker can send specially crafted packets to trigger a heap-based buffer overflow, potentially leading to remote code execution.

Exploitation Likelihood: MEDIUM

Affected Products
VendorProductFixed Version
Fortinet Fortios
Fortinet Fortiswitchmanager
Fortinet Fortisase
Fujitsu-Siemens —
Siemens —
Remediation
View Vendor Advisory →

Remediation Priority: IMMEDIATE

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 193 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
● Virtual Patch — CITED Relevance SAGE Engine MEDIUM CONFIDENCE

Implement network segmentation and access controls to limit exposure to untrusted networks. Apply the latest security patches and updates from Fortinet as soon as they are available.

No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. SAGE only publishes a network rule when a concrete on-the-wire signature can be grounded in the advisory.

NERC CIP: CIP-007 CIP-007-R2
This vulnerability could allow an attacker to gain unauthorized access to critical systems, violating the requirement for secure access controls and the protection of critical cyber assets.
IEC 62443: SR 7.6
The vulnerability poses a significant risk to the integrity and availability of the control system, which is a key requirement under IEC 62443-4-2 for secure system design and implementation.

Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.

SAGE Enrichment Record — provenance & audit hash
ModelQwen/Qwen2.5-72B-Instruct-AWQ
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hashbb76759a38b672919dba06167c6740f991ecb678602360f0bb501cda59f16398c46fa2ff683fa713b04aa4ba92dad03e5f75df707ba8330c1ba19d33b5589d62
Related CVEs affecting Fortinet
CVE-2005-3057 10.0 The FTP component in FortiGate 2.8 running FortiOS 2.8MR10 and v3beta, and ot... CVE-2024-47575 9.8 A missing authentication for critical function in FortiManager 7.6.0, FortiMa... CVE-2024-23109 9.8 An improper neutralization of special elements used in an os command ('os com... CVE-2024-23108 9.8 An improper neutralization of special elements used in an os command ('os com... CVE-2019-16153 9.8 A hard-coded password vulnerability in the Fortinet FortiSIEM database compon...
View all Fortinet CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →