← All Advisories

CVE-2025-25249: Fortinet Multiple Products

Status: KEV  |  Advisory ID: CVE-2025-25249

Key Details

CVECVE-2025-25249
CVSSCVSS 8.1 (High): attack vector is network; attack complexity is high; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high. (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Affected productsFortinet Multiple Products, Fortinet FortiOS, Fortinet FortiSwitchManager, Fortinet FortiSASE, and Siemens RUGGEDCOM APE1808 Firmware
Exploitation statusListed in CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed active exploitation.
KEV listingAdded to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2026-09-09.

What to Know

A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2025-25249
Vendor advisoryhttps://fortiguard.fortinet.com/psirt/FG-IR-25-084