SB2025070845 - Heap-based buffer overflow in FortiOS
Published: July 8, 2025
Security Bulletin ID
SB2025070845
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Local access
Highest impact
Data manipulation
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Heap-based buffer overflow (CVE-ID: CVE-2025-24477)
The vulnerability allows a local privileged user to read and manipulate data.
The vulnerability exists due to heap-based buffer overflow in cw_stad daemon. An authenticated attacker can execute arbitrary code or commands via specifically crafted requests.
The following models are impacted if configured as a as a wireless client :
- FWF_80F_2R_3G4G_DSL
- FWF_80F_2R
- FWF_81F_2R_3G4G_DSL
- FWF_81F_2R_3G4G_POE
- FWF_81F_2R
- FWF_81F_2R_POE
- FWF_90G_2R
- FWF_91G_2R
Remediation
Install update from vendor's website.