ID:11620 - Exploit for Stack-based buffer overflow in Fortinet, Inc products - CVE-2025-32756

 
Main Vulnerability Database Exploits ID:11620 - Exploit for Stack-based buffer overflow in Fortinet, Inc products - CVE-2025-32756

ID:11620 - Exploit for Stack-based buffer overflow in Fortinet, Inc products - CVE-2025-32756

Published: June 13, 2025


Vulnerability identifier: #VU109101
Vulnerability risk: Critical
CVE-ID: CVE-2025-32756
CWE-ID: CWE-121
Exploitation vector: Remote access
Vulnerable software:
FortiCamera
FortiMail
FortiNDR
FortiRecorder
FortiVoice

Link to public exploit:


Vulnerability description

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

The vulnerability exists due to stack-based buffer overflow in API. A remote unauthenticated attacker can execute arbitrary code or commands via crafted HTTP requests.

Note, this vulnerability is being actively exploited in the wild against FortiVoice instances.


Remediation

Install update from vendor's website.