---
id: CVE-2025-25249
title: >-
  A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through
  7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS
  7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0
  through 7.2.6…
summary: >-
  A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through
  7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS
  7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0
  through 7.2.6…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-122
  - CWE-787
vendor: fortinet
product: fortiswitchmanager
affected:
  - 'fortios >= 6.4.0, < 7.0.18'
  - 'fortios >= 7.2.0, < 7.2.12'
  - 'fortios >= 7.4.0, < 7.4.9'
  - 'fortios >= 7.6.0, < 7.6.4'
  - 'fortiswitchmanager >= 7.0.0, < 7.0.6'
  - 'fortiswitchmanager >= 7.2.0, < 7.2.7'
  - fortisase = 25.1.39
  - fortisase = 25.1.51
  - ruggedcom_ape1808_firmware
patched:
  - fortios 7.6.4
  - fortiswitchmanager 7.2.7
published: '2026-01-13'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T12:47:59.933'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-25249'
references:
  - url: 'https://fortiguard.fortinet.com/psirt/FG-IR-25-084'
    label: psirt@fortinet.com
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-864900.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
  - url: 'https://socradar.io/blog/cve-2025-25249-pivotc2-fortigate-rat/'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-25249
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - in-the-wild
  - exploit-available
  - kev
exploited: true
exploitAvailable: true
ssvc:
  exploitation: active
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-09T19:50:11.566505Z'
scores:
  nvd: 8.1
  cna: 7.4
epss: 0.03859
epssPercentile: 0.89779
kev: true
kevDateAdded: '2026-09-09'
kevDueDate: '2026-09-12'
kevRansomware: false
ingestedAt: '2026-09-09T20:21:14.797Z'
---

## Overview

A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets

## Affected

- `fortios >= 6.4.0, < 7.0.18`
- `fortios >= 7.2.0, < 7.2.12`
- `fortios >= 7.4.0, < 7.4.9`
- `fortios >= 7.6.0, < 7.6.4`
- `fortiswitchmanager >= 7.0.0, < 7.0.6`
- `fortiswitchmanager >= 7.2.0, < 7.2.7`
- `fortisase = 25.1.39`
- `fortisase = 25.1.51`
- `ruggedcom_ape1808_firmware`

## Remediation

Upgrade past the affected range:

- `fortios 7.6.4`
- `fortiswitchmanager 7.2.7`
