First published · Last updated
CVE-2025-25249: Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
A heap-based buffer overflow in Fortinet FortiOS, FortiSwitchManager, and FortiSASE can allow an attacker to execute unauthorized code or commands via specially crafted packets. The source requires applying vendor mitigations and following CISA BOD 26-04 and forensics triage guidance.
Categories: technology
Generated scores
Scores are based on the cited reporting and use a 1–10 scale. Read the methodology.
- Confidence
- 6/10
- Geographic reach
- 4/10
- Global importance
- 5/10
- Impact magnitude
- 6/10
- Positivity
- 2/10
- Urgency
- 7/10
Why it matters
Required mitigations and adherence to CISA patching directives are mandated to address remote code execution risks in multiple Fortinet products.

