Junglewise Threat Intelligence

CVE-2025-25249: Fortinet FortiOS heap overflow in cw_acd daemon

CVE-2025-25249 · Severity: critical · CVSS 8.1 · Exploited in the wild · Published 2026-01-13

Technologies: Siemens Ruggedcom Ape1808, Fortinet FortiOS, Fortinet FortiSwitchManager, Fortinet Fortisase. Vendors: Siemens, Fortinet.

Executive brief

Fortinet FortiOS and related security appliances contain a heap-based buffer overflow vulnerability in packet processing that allows remote attackers to execute arbitrary code. Exploitation has been observed in the wild, making this an active threat to organizations relying on these products for network security and management.

Technical details

A heap-based buffer overflow exists in the packet processing functionality of Fortinet FortiOS, FortiSwitchManager, and FortiSASE. The vulnerability is triggered when the affected products process specially crafted network packets, leading to memory corruption on the heap. An unauthenticated remote attacker on the network can exploit this vulnerability without user interaction to achieve arbitrary code execution with the privileges of the vulnerable process. The vulnerability is being actively exploited in the wild, indicating broad availability of exploit code or techniques.

Affected products

  • Fortinet FortiOS
  • Fortinet FortiSwitchManager
  • Fortinet FortiSASE

Timeline

  • 2026-09-09: disclosed
  • exploited: Active exploitation reported in the wild

Related threats