#VU109101 Stack-based buffer overflow in Fortinet, Inc products - CVE-2025-32756

 

#VU109101 Stack-based buffer overflow in Fortinet, Inc products - CVE-2025-32756

Published: May 13, 2025 / Updated: June 13, 2025


Vulnerability identifier: #VU109101
Vulnerability risk: Critical
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A/U:Red
CVE-ID: CVE-2025-32756
CWE-ID: CWE-121
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild
Vulnerable software:
FortiCamera
FortiMail
FortiNDR
FortiRecorder
FortiVoice
Software vendor:
Fortinet, Inc

Description

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

The vulnerability exists due to stack-based buffer overflow in API. A remote unauthenticated attacker can execute arbitrary code or commands via crafted HTTP requests.

Note, this vulnerability is being actively exploited in the wild against FortiVoice instances.


Remediation

Install update from vendor's website.

External links