Junglewise Threat Intelligence

CVE-2025-32756: Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability

CVE-2025-32756 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2025-05-14

Technologies: Apple Multiple Products. Vendors: Fortinet, Apple.

Executive brief

A stack-based buffer overflow vulnerability in multiple Fortinet products allows a remote unauthenticated attacker to execute arbitrary code or commands. The exploit is triggered by sending HTTP requests containing a specially crafted hash cookie.

Affected products

  • Fortinet FortiCamera 2.1.0 through 2.1.3, 2.0 all versions, 1.1 all versions
  • Fortinet FortiMail 7.6.0 through 7.6.2, 7.4.0 through 7.4.4, 7.2.0 through 7.2.7, 7.0.0 through 7.0.8
  • Fortinet FortiNDR 7.6.0, 7.4.0 through 7.4.7, 7.2.0 through 7.2.4, 7.0.0 through 7.0.6
  • Fortinet FortiRecorder 7.2.0 through 7.2.3, 7.0.0 through 7.0.5, 6.4.0 through 6.4.5
  • Fortinet FortiVoice 7.2.0, 7.0.0 through 7.0.6, 6.4.0 through 6.4.10

Timeline

  • 2025-05-14: disclosed
  • 2025-05-14: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2025-05-14: exploited: Reported as exploited in the wild at time of publication.

Related threats