High severity8.1CISA KEVNVD Advisory· Published Jan 13, 2026· Updated Sep 10, 2026
CVE-2025-25249
CVE-2025-25249
Description
A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
87.6.0 through 7.6.3, 7.4.0 through 7.4.8, 7.2.0 through 7.2.11, 7.0.0 through 7.0.17, 6.4 all versions+ 2 more
- (no CPE)range: 7.6.0 through 7.6.3, 7.4.0 through 7.4.8, 7.2.0 through 7.2.11, 7.0.0 through 7.0.17, 6.4 all versions
- cpe:2.3:o:fortinet:fortios:7.6.2:*:*:*:*:*:*:*range: 7.6.0
- cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*range: >=6.4.0,<6.4.17
7.2.0 through 7.2.6, 7.0.0 through 7.0.5+ 2 more
- (no CPE)range: 7.2.0 through 7.2.6, 7.0.0 through 7.0.5
- cpe:2.3:a:fortinet:fortiswitchmanager:7.2.5:*:*:*:*:*:*:*range: 7.2.2
- cpe:2.3:a:fortinet:fortiswitchmanager:*:*:*:*:*:*:*:*range: >=7.0.0,<7.0.6
Patches
Vulnerability mechanics
References
4- socradar.io/blog/cve-2025-25249-pivotc2-fortigate-rat/nvdExploitThird Party Advisory
- cert-portal.siemens.com/productcert/html/ssa-864900.htmlnvdThird Party Advisory
- fortiguard.fortinet.com/psirt/FG-IR-25-084nvdVendor AdvisoryMitigation
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
9- Weekly Cybersecurity Newsletter Bulletin – Cisco and Android 0-Day, BragJack Attack, Claude Opus 5 Used to Hack OpenAI, and 20+ StoriesCyber Security News · Sep 21, 2026
- Hackers Allegedly Selling Fortinet FortiGate 1-Day Vulnerability on Underground ForumsCyber Security News · Sep 17, 2026
- Weekly Cybersecurity Newsletter Bulletin – Microsoft 0-day, FortiOS, PAN-OS Flaw, Revolut Data Breach, and 20+ StoriesCyber Security News · Sep 14, 2026
- CISA Warns of Fortinet Heap-based Buffer Overflow Flaw Exploited in AttacksCyber Security News · Sep 10, 2026
- CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch DeadlineThe Hacker News · Sep 10, 2026
- Fortinet Code Execution Flaw Exploited in PivotC2 RAT AttacksSecurityWeek · Sep 10, 2026
- Fortinet CVE-2025-25249 Zero-Day Added to CISA KEV Under Active ExploitationVypr Intelligence · Sep 9, 2026
- Hackers Actively Exploiting FortiGate Firewalls to Deploy Custom Node.js MalwareCyber Security News · Sep 8, 2026
- CISA Adds Four Known Exploited Vulnerabilities to CatalogCISA Alerts