Executive brief
A stack-based buffer overflow vulnerability in multiple Fortinet products allows a remote unauthenticated attacker to execute arbitrary code or commands. The exploit is triggered by sending HTTP requests containing a specially crafted hash cookie.
Affected products
- Fortinet FortiCamera 2.1.0 through 2.1.3, 2.0 all versions, 1.1 all versions
- Fortinet FortiMail 7.6.0 through 7.6.2, 7.4.0 through 7.4.4, 7.2.0 through 7.2.7, 7.0.0 through 7.0.8
- Fortinet FortiNDR 7.6.0, 7.4.0 through 7.4.7, 7.2.0 through 7.2.4, 7.0.0 through 7.0.6
- Fortinet FortiRecorder 7.2.0 through 7.2.3, 7.0.0 through 7.0.5, 6.4.0 through 6.4.5
- Fortinet FortiVoice 7.2.0, 7.0.0 through 7.0.6, 6.4.0 through 6.4.10
Timeline
- 2025-05-14: disclosed
- 2025-05-14: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2025-05-14: exploited: Reported as exploited in the wild at time of publication.