Vulnerability record · CVE-2025-25249 · published 13 January 2026
CVE-2025-25249: Fortinet FortiOS and FortiSwitchManager heap buffer overflow via crafted packets
Fortinet · Fortios
A heap-based buffer overflow (CWE-122/CWE-787) in Fortinet FortiOS 6.4 through 7.6.3 and FortiSwitchManager 7.0 through 7.2.6 lets an unauthenticated remote attacker trigger memory corruption through specially crafted packets. The flaw carries a CVSS 3.1 score of 9.8 and is listed in CISA KEV, so it warrants urgent patching on any internet-exposed instance.
Description
A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 unauthenticated remote code execution on perimeter security appliances combined with CISA KEV listing and an exploit-tagged reference makes this an urgent patch target.
What it is
A heap-based buffer overflow (CWE-122/CWE-787) in Fortinet FortiOS 6.4 through 7.6.3 and FortiSwitchManager 7.0 through 7.2.6 lets an unauthenticated remote attacker trigger memory corruption through specially crafted packets. The flaw carries a CVSS 3.1 score of 9.8 and is listed in CISA KEV, so it warrants urgent patching on any internet-exposed instance.
Impact
Successful exploitation allows execution of unauthorized code or commands on the affected device, giving an attacker a foothold on a perimeter security appliance. Full compromise of confidentiality, integrity and availability is possible per the CVSS vector.
Attack surface
Reachable over the network with no authentication and no user interaction (AV:N/AC:L/PR:N/UI:N), via crafted packets sent to the affected FortiOS or FortiSwitchManager service. Any instance exposed to untrusted networks is a candidate target.
Exploitation
CVE-2025-25249 is in CISA KEV with a due date of 2026-09-12, and a third-party reference is tagged Exploit, indicating observed exploitation; EPSS 30-day probability is 0.024 (83rd percentile). No ransomware campaign use is documented.
What to do
- Apply the Fortinet PSIRT FG-IR-25-084 firmware updates for FortiOS and FortiSwitchManager as the first action.
- If immediate patching is not possible, follow CISA BOD 26-04 guidance and the vendor mitigation instructions, or discontinue use of the exposed product.
- Remove management and service interfaces from direct internet exposure and restrict access to trusted networks.
- Track Siemens advisory SSA-864900 for the affected Ruggedcom APE1808 firmware and apply the corresponding fix.
- Verify patched status across all FortiOS 6.4, 7.0, 7.2, 7.4, 7.6 and FortiSwitchManager 7.0/7.2 assets, including FortiSASE deployments.
Detection
- Hunt for crashes, restarts or unexpected process terminations on FortiOS and FortiSwitchManager devices that could indicate heap corruption attempts.
- Monitor network traffic to exposed Fortinet management and service ports for anomalous or malformed packet patterns.
- Review device logs for unauthorized command execution, new local accounts or configuration changes following suspicious packet activity.
- Correlate KEV due-date compliance reporting to confirm all affected assets are patched within the CISA deadline.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-25249 to the Known Exploited Vulnerabilities catalog on 9 September 2026 as "Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 12 September 2026.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-25-084 | Vendor AdvisoryMitigation |
| https://cert-portal.siemens.com/productcert/html/ssa-864900.html | Third Party Advisory |
| https://socradar.io/blog/cve-2025-25249-pivotc2-fortigate-rat/ | ExploitThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-25249 | US Government Resource |
Track CVE-2025-25249 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-25249), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.