FortiOS heap overflow, exploited in the wild (CVE-2025-25249)
CVE-2025-25249
CVE-2025-25249: FortiOS 6.4 through 7.6.3 heap buffer overflow lets remote attackers run code (CVSS 9.8). Actively exploited; update to fixed releases now.
Actively exploited in the wild - CVE-2025-25249 is a critical heap-based buffer overflow in Fortinet FortiOS 7.6.0 through 7.6.3, 7.4.0 through 7.4.8, 7.2.0 through 7.2.11, 7.0.0 through 7.0.17, and all 6.4 versions, plus FortiSwitchManager 7.2.0 through 7.2.6 and 7.0.0 through 7.0.5, that grants attackers unauthorized code execution or command execution via specially crafted packets. Fortinet has shipped fixed releases; treat any exposed management interface as compromised until proven otherwise.
Overview
CVE-2025-25249 is a memory corruption bug in Fortinet’s FortiOS and FortiSwitchManager. When the affected software processes a specially crafted network packet, it writes more data into a heap buffer than that buffer can hold. That overflow lets an attacker overwrite adjacent memory and, in the worst case, redirect execution to attacker-controlled code running with the privileges of the vulnerable service.
The CVSS score is 9.8. The vector shows network reachability with no privileges and no user interaction required, though attack complexity is rated HIGH, meaning an attacker needs to win a race or satisfy specific memory layout conditions to land a reliable exploit. High complexity raises the skill bar but does not remove the risk, especially for a target this widely deployed.
Impact
Successful exploitation lets an attacker execute unauthorized code or commands on the device. On a firewall or switch manager, that is close to worst case: these systems sit on the network edge, hold VPN credentials, route traffic between trust zones, and often act as the enforcement point for the whole security policy. An attacker who controls one can silently redirect or decrypt traffic, pivot deeper into the network, and tamper with logging so the intrusion is harder to spot.
Because this is confirmed as an actively exploited vulnerability in CISA’s Known Exploited Vulnerabilities catalog, defenders should not treat it as theoretical. An EPSS score of roughly 0.8 percent reflects broad population probability, not the risk to any single exposed appliance - targeted exploitation against internet-facing management interfaces can be far more likely than the aggregate number suggests.
Remediation and Mitigation
- Upgrade FortiOS to a fixed build within your release train (7.6.4 or later, 7.4.9 or later, 7.2.12 or later, 7.0.18 or later) and move off 6.4, which is end of support.
- Update FortiSwitchManager to a patched release (7.2.7 or later, 7.0.6 or later).
- Never expose administrative interfaces to the internet. Restrict management access to a dedicated out-of-band network and trusted source IPs.
- Review logs for unexpected configuration changes, new admin accounts, or unexplained outbound connections, and rotate credentials for any device that may have been exposed.
- Hunt for indicators of compromise consistent with prior Fortinet edge-device campaigns, which follow the pattern seen in Threat Actors Exploit Critical FortiClient EMS Flaw to.
Security Insight
This is the latest entry in a long-running pattern: Fortinet edge appliances are repeatedly found in CISA’s KEV catalog, and attackers treat them as high-value, hard-to-remediate footholds because patching an internet-facing firewall often means a maintenance window rather than a routine reboot. That friction - combined with the fact that a compromised appliance can rewrite its own logs - is what makes these devices attractive, and it echoes the same operational reality seen across recent edge-device incidents covered in our Weekly Threat Roundup: Nx Console Supply Chain Attack (May 25-31). Defenders should assume edge devices are a primary target and build detection for them accordingly, rather than waiting for the next advisory.
Further Reading
Never miss a critical vulnerability
Get real-time security alerts delivered to your preferred platform.
Related Advisories
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, Fort...
SD-330AC and AMC Manager provided by silex technology, Inc. contain a heap-based buffer overflow vulnerability in processing the redirect URLs. Arbitrary code may be executed on the device....
Heap buffer overflow in ANGLE in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)...
A heap-based buffer overflow vulnerability exists in the Intan CLP parsing functionality of The Biosig Project libbiosig 3.9.2 and Master Branch (db9a9a63). A specially crafted Intan CLP file can lead...