Heap-based buffer overflow in Fortinet, Inc products - CVE-2025-22258
Published: October 15, 2025
Vulnerability identifier: #VU117143
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-22258
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote privileged user to damange or delete data.
The vulnerability exists due to heap-based buffer overflow in websocket. An authenticated attacker can execute arbitrary code or commands via specifically crafted requests.
Affected software
FortiPAM
FortiSRA
FortiOS
FortiSwitch Manager
FortiProxy
FortiSRA
FortiOS
FortiSwitch Manager
FortiProxy
How to mitigate CVE-2025-22258
Install update from vendor's website.
FortiPAM - addressed in versions 1.4.3, 1.5.1
FortiSRA - addressed in versions 1.4.3, 1.5.1
FortiOS - addressed in versions 7.0.17, 7.2.11, 7.4.7, 7.6.3
FortiSwitch Manager - update to 7.2.6
FortiProxy - addressed in versions 7.4.8, 7.6.2
FortiSRA - addressed in versions 1.4.3, 1.5.1
FortiOS - addressed in versions 7.0.17, 7.2.11, 7.4.7, 7.6.3
FortiSwitch Manager - update to 7.2.6
FortiProxy - addressed in versions 7.4.8, 7.6.2