LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-32756: Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability

RBRecent Breaches Vulnerability Intelligence·May 14, 2025
CVSS 9.8 · Critical⚠ Actively exploited (CISA KEV)
9.8
CVSS score
Critical
Severity
Active
CISA KEV
No
Ransomware use
Jun 4, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-32756 to its Known Exploited Vulnerabilities catalog on May 14, 2025, with a federal patch deadline of Jun 4, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiCamera 1.1 all versions, FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail 7.0.0 through 7.0.8, FortiNDR 7.6.0, FortiNDR 7.4.0 through 7.4.7, FortiNDR 7.2.0 through 7.2.4, FortiNDR 7.0.0 through 7.0.6, FortiRecorder 7.2.0 through 7.2.3, FortiRecorder 7.0.0 through 7.0.5, FortiRecorder 6.4.0 through 6.4.5, FortiVoice 7.2.0, FortiVoice 7.0.0 through 7.0.6, FortiVoice 6.4.0 through 6.4.10 allows a remote unauthenticated attacker to execute arbitrary code or commands via sending HTTP requests with specially crafted hash cookie.

CVE-2025-32756 is a stack-based buffer overflow in multiple Fortinet products—specifically FortiFone, FortiVoice, FortiNDR, and FortiMail—that can let a remote unauthenticated attacker execute arbitrary code or commands by sending crafted HTTP requests. Because these products often sit on network edges or handle voice, mail, and detection traffic, successful exploitation can give an attacker a foothold without credentials. Confirm exact product coverage and fixed builds against the vendor advisory before acting.

CISA notes that organizations should apply vendor mitigations, follow BOD 22-01 guidance for any cloud-hosted instances, or discontinue use if no mitigations exist. Ransomware use of this CVE is not documented in the available facts.

How it works

The weakness is classified as CWE-124 and described as a stack-based overflow. In this class of flaw, an application fails to properly bound data written onto the stack. An attacker who can reach the vulnerable HTTP-handling code can supply oversized or specially formed request data that overruns the allocated stack buffer. When the overflow succeeds, it can overwrite return addresses or other control data, allowing the attacker to redirect execution to code of their choosing or to inject commands that the process then runs.

Because the attack requires only crafted HTTP requests and no authentication, any interface that accepts such requests from untrusted networks is a potential entry point. Exact request formats, affected endpoints, and memory-layout details are not provided in the public summary; treat the vendor advisory as the authoritative source for those mechanics.

Am I affected? How to find it in your systems

These Fortinet products typically appear in enterprise voice, messaging, network detection, and email security deployments. FortiVoice and FortiFone often run as appliances or virtual instances supporting telephony; FortiMail handles email gateway or security functions; FortiNDR provides network detection and response. Inventory every instance that accepts HTTP or HTTPS management or service traffic.

If version or configuration details are unclear, treat the system as potentially affected until the vendor advisory confirms otherwise.

How to remediate

Patch first. Obtain and install the vendor-supplied update that addresses CVE-2025-32756 for each affected product. Follow the installation and reboot guidance in the Fortinet advisory exactly; do not assume a generic FortiOS or other Fortinet patch covers these specific products.

Document the change and re-scan the environment to confirm no unpatched instances remain.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls:

If your data may have been exposed

Actively exploited remote-code-execution vulnerabilities frequently lead to full system compromise and subsequent data theft or lateral movement. If logs or other indicators suggest successful exploitation, treat the appliance and any systems it could reach as potentially breached: isolate them, preserve forensic evidence, and begin incident-response procedures. As a quick personal check, you can run a free exposure scan of your email address against known breach data sets to see whether credentials or other information associated with your accounts have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedFortinet · Multiple Products
WeaknessCWE-121
CVSS base score9.8 (Critical)
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
PublishedMay 13, 2025
Added to CISA KEVMay 14, 2025
Federal patch deadlineJun 4, 2025
Known ransomware useNot documented
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities