// For flags

CVE-2025-32756

Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability

Severity Score

9.6
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

Yes
*KEV

Decision

Act
*SSVC
Descriptions

A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiVoice versions 7.2.0, 7.0.0 through 7.0.6, 6.4.0 through 6.4.10, FortiRecorder versions 7.2.0 through 7.2.3, 7.0.0 through 7.0.5, 6.4.0 through 6.4.5, FortiMail versions 7.6.0 through 7.6.2, 7.4.0 through 7.4.4, 7.2.0 through 7.2.7, 7.0.0 through 7.0.8, FortiNDR versions 7.6.0, 7.4.0 through 7.4.7, 7.2.0 through 7.2.4, 7.0.0 through 7.0.6, FortiCamera versions 2.1.0 through 2.1.3, 2.0 all versions, 1.1 all versions, allows a remote unauthenticated attacker to execute arbitrary code or commands via sending HTTP requests with specially crafted hash cookie.

Fortinet FortiFone, FortiVoice, FortiNDR and FortiMail contain a stack-based overflow vulnerability that may allow a remote unauthenticated attacker to execute arbitrary code or commands via crafted HTTP requests.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:Act
Exploitation
Active
Automatable
Yes
Tech. Impact
Total
* Organization's Worst-case Scenario
Timeline
  • 2025-04-10 CVE Reserved
  • 2025-05-13 CVE Published
  • 2025-05-14 Exploited in Wild
  • 2025-05-15 CVE Updated
  • 2025-05-19 EPSS Updated
  • 2025-06-04 KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-121: Stack-based Buffer Overflow
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Fortinet
Search vendor "Fortinet"
FortiVoice
Search vendor "Fortinet" for product "FortiVoice"
7.2.0
Search vendor "Fortinet" for product "FortiVoice" and version "7.2.0"
en
Affected
Fortinet
Search vendor "Fortinet"
FortiVoice
Search vendor "Fortinet" for product "FortiVoice"
>= 7.0.0 <= 7.0.6
Search vendor "Fortinet" for product "FortiVoice" and version " >= 7.0.0 <= 7.0.6"
en
Affected
Fortinet
Search vendor "Fortinet"
FortiVoice
Search vendor "Fortinet" for product "FortiVoice"
>= 6.4.0 <= 6.4.10
Search vendor "Fortinet" for product "FortiVoice" and version " >= 6.4.0 <= 6.4.10"
en
Affected
Fortinet
Search vendor "Fortinet"
FortiRecorder
Search vendor "Fortinet" for product "FortiRecorder"
>= 7.2.0 <= 7.2.3
Search vendor "Fortinet" for product "FortiRecorder" and version " >= 7.2.0 <= 7.2.3"
en
Affected
Fortinet
Search vendor "Fortinet"
FortiRecorder
Search vendor "Fortinet" for product "FortiRecorder"
>= 7.0.0 <= 7.0.5
Search vendor "Fortinet" for product "FortiRecorder" and version " >= 7.0.0 <= 7.0.5"
en
Affected
Fortinet
Search vendor "Fortinet"
FortiRecorder
Search vendor "Fortinet" for product "FortiRecorder"
>= 6.4.0 <= 6.4.5
Search vendor "Fortinet" for product "FortiRecorder" and version " >= 6.4.0 <= 6.4.5"
en
Affected
Fortinet
Search vendor "Fortinet"
FortiMail
Search vendor "Fortinet" for product "FortiMail"
>= 7.6.0 <= 7.6.2
Search vendor "Fortinet" for product "FortiMail" and version " >= 7.6.0 <= 7.6.2"
en
Affected
Fortinet
Search vendor "Fortinet"
FortiMail
Search vendor "Fortinet" for product "FortiMail"
>= 7.4.0 <= 7.4.4
Search vendor "Fortinet" for product "FortiMail" and version " >= 7.4.0 <= 7.4.4"
en
Affected
Fortinet
Search vendor "Fortinet"
FortiMail
Search vendor "Fortinet" for product "FortiMail"
>= 7.2.0 <= 7.2.7
Search vendor "Fortinet" for product "FortiMail" and version " >= 7.2.0 <= 7.2.7"
en
Affected
Fortinet
Search vendor "Fortinet"
FortiMail
Search vendor "Fortinet" for product "FortiMail"
>= 7.0.0 <= 7.0.8
Search vendor "Fortinet" for product "FortiMail" and version " >= 7.0.0 <= 7.0.8"
en
Affected
Fortinet
Search vendor "Fortinet"
FortiNDR
Search vendor "Fortinet" for product "FortiNDR"
7.6.0
Search vendor "Fortinet" for product "FortiNDR" and version "7.6.0"
en
Affected
Fortinet
Search vendor "Fortinet"
FortiNDR
Search vendor "Fortinet" for product "FortiNDR"
>= 7.4.0 <= 7.4.7
Search vendor "Fortinet" for product "FortiNDR" and version " >= 7.4.0 <= 7.4.7"
en
Affected
Fortinet
Search vendor "Fortinet"
FortiNDR
Search vendor "Fortinet" for product "FortiNDR"
>= 7.2.0 <= 7.2.4
Search vendor "Fortinet" for product "FortiNDR" and version " >= 7.2.0 <= 7.2.4"
en
Affected
Fortinet
Search vendor "Fortinet"
FortiNDR
Search vendor "Fortinet" for product "FortiNDR"
>= 7.1.0 <= 7.1.1
Search vendor "Fortinet" for product "FortiNDR" and version " >= 7.1.0 <= 7.1.1"
en
Affected
Fortinet
Search vendor "Fortinet"
FortiNDR
Search vendor "Fortinet" for product "FortiNDR"
>= 7.0.0 <= 7.0.6
Search vendor "Fortinet" for product "FortiNDR" and version " >= 7.0.0 <= 7.0.6"
en
Affected
Fortinet
Search vendor "Fortinet"
FortiNDR
Search vendor "Fortinet" for product "FortiNDR"
>= 1.5.0 <= 1.5.3
Search vendor "Fortinet" for product "FortiNDR" and version " >= 1.5.0 <= 1.5.3"
en
Affected
Fortinet
Search vendor "Fortinet"
FortiNDR
Search vendor "Fortinet" for product "FortiNDR"
1.4.0
Search vendor "Fortinet" for product "FortiNDR" and version "1.4.0"
en
Affected
Fortinet
Search vendor "Fortinet"
FortiNDR
Search vendor "Fortinet" for product "FortiNDR"
>= 1.3.0 <= 1.3.1
Search vendor "Fortinet" for product "FortiNDR" and version " >= 1.3.0 <= 1.3.1"
en
Affected
Fortinet
Search vendor "Fortinet"
FortiNDR
Search vendor "Fortinet" for product "FortiNDR"
1.2.0
Search vendor "Fortinet" for product "FortiNDR" and version "1.2.0"
en
Affected
Fortinet
Search vendor "Fortinet"
FortiNDR
Search vendor "Fortinet" for product "FortiNDR"
1.1.0
Search vendor "Fortinet" for product "FortiNDR" and version "1.1.0"
en
Affected
Fortinet
Search vendor "Fortinet"
FortiCamera
Search vendor "Fortinet" for product "FortiCamera"
>= 2.1.0 <= 2.1.3
Search vendor "Fortinet" for product "FortiCamera" and version " >= 2.1.0 <= 2.1.3"
en
Affected
Fortinet
Search vendor "Fortinet"
FortiCamera
Search vendor "Fortinet" for product "FortiCamera"
2.0.0
Search vendor "Fortinet" for product "FortiCamera" and version "2.0.0"
en
Affected
Fortinet
Search vendor "Fortinet"
FortiCamera
Search vendor "Fortinet" for product "FortiCamera"
>= 1.1.0 <= 1.1.5
Search vendor "Fortinet" for product "FortiCamera" and version " >= 1.1.0 <= 1.1.5"
en
Affected