CVE-2025-25249
HIGH · 8.1 KEV EPSS 2.4%KEV-confirmed active exploitation, post-exploitation RAT observed, threat research corroboration, urgent patching signals.
What: Heap-based buffer overflow in Fortinet FortiOS 7.6.0–7.0.0 and FortiSwitchManager 7.2.0–7.0.0 allows remote code execution via malformed packets (CVSS 8.1).
Why it matters: KEV-listed as actively exploited (added 2026-09-09). SOCRadar reported threat actors deploying PivotC2 RAT post-exploitation in the wild. CISA alert confirms active exploitation. Fortinet firmware across multiple versions is affected; patching is urgent for defenders.
Where it's seen: CISA KEV announcement, SOCRadar threat research advisory reporting post-exploitation RAT deployment, security monitoring platforms (cvemon) tracking as trending. Repeated calls for urgent patching across infosec community.
RISK: CRITICAL — Actively exploited heap overflow in critical appliances, RAT deployment observed, KEV-listed, no low-version bypass.
Description
A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets
CVSS 3.1 breakdown
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H- Attack vector
- Network
- Complexity
- High
- Privileges required
- None
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- High
- Availability
- High
Affected versions
- fortinet/fortios
- 6.4.0 – < 6.4.17
- 7.0.0 – < 7.0.18
- 7.2.0 – < 7.2.12
- 7.4.0 – < 7.4.9
- 7.6.0 – < 7.6.4
- fortinet/fortiswitchmanager
- 7.0.0 – < 7.0.6
- 7.2.0 – < 7.2.7
- fortinet/fortisase
- 25.1.39
- 25.1.51