Stack-based buffer overflow in Fortinet, Inc products - CVE-2025-32756
Published: May 13, 2025 / Updated: June 13, 2025
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
The vulnerability exists due to stack-based buffer overflow in API. A remote unauthenticated attacker can execute arbitrary code or commands via crafted HTTP requests.
Note, this vulnerability is being actively exploited in the wild against FortiVoice instances.
Affected software
FortiMail
FortiCamera
FortiVoice
FortiRecorder
How to mitigate CVE-2025-32756
FortiCamera - update to 2.1.4
FortiVoice - addressed in versions 6.4.11, 7.0.7, 7.2.1
FortiRecorder - addressed in versions 6.4.6, 7.0.6, 7.2.4
FortiMail - addressed in versions 7.0.9, 7.2.8, 7.4.5, 7.6.3