CVE-2025-32756: Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiCamera 1.1 all versions, FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail 7.0.0 through 7.0.8, FortiNDR 7.6.0, FortiNDR 7.4.0 through 7.4.7, FortiNDR 7.2.0 through 7.2.4, FortiNDR 7.0.0 through 7.0.6, FortiRecorder 7.2.0 through 7.2.3, FortiRecorder 7.0.0 through 7.0.5, FortiRecorder 6.4.0 through 6.4.5, FortiVoice 7.2.0, FortiVoice 7.0.0 through 7.0.6, FortiVoice 6.4.0 through 6.4.10 allows a remote unauthenticated attacker to execute arbitrary code or commands via sending HTTP requests with specially crafted hash cookie.
CVE-2025-32756 is a stack-based buffer overflow in multiple Fortinet products—specifically FortiFone, FortiVoice, FortiNDR, and FortiMail—that can let a remote unauthenticated attacker execute arbitrary code or commands by sending crafted HTTP requests. Because these products often sit on network edges or handle voice, mail, and detection traffic, successful exploitation can give an attacker a foothold without credentials. Confirm exact product coverage and fixed builds against the vendor advisory before acting.
CISA notes that organizations should apply vendor mitigations, follow BOD 22-01 guidance for any cloud-hosted instances, or discontinue use if no mitigations exist. Ransomware use of this CVE is not documented in the available facts.
How it works
The weakness is classified as CWE-124 and described as a stack-based overflow. In this class of flaw, an application fails to properly bound data written onto the stack. An attacker who can reach the vulnerable HTTP-handling code can supply oversized or specially formed request data that overruns the allocated stack buffer. When the overflow succeeds, it can overwrite return addresses or other control data, allowing the attacker to redirect execution to code of their choosing or to inject commands that the process then runs.
Because the attack requires only crafted HTTP requests and no authentication, any interface that accepts such requests from untrusted networks is a potential entry point. Exact request formats, affected endpoints, and memory-layout details are not provided in the public summary; treat the vendor advisory as the authoritative source for those mechanics.
Am I affected? How to find it in your systems
These Fortinet products typically appear in enterprise voice, messaging, network detection, and email security deployments. FortiVoice and FortiFone often run as appliances or virtual instances supporting telephony; FortiMail handles email gateway or security functions; FortiNDR provides network detection and response. Inventory every instance that accepts HTTP or HTTPS management or service traffic.
- Query asset-management, CMDB, and network-discovery tools for Fortinet devices or virtual appliances labeled FortiFone, FortiVoice, FortiNDR, or FortiMail.
- Check management consoles, license portals, and CLI version commands for the software build currently running; compare those builds against the fixed versions listed in the vendor advisory.
- Identify any instances exposed to the internet or to untrusted internal segments, especially those listening on HTTP/HTTPS ports used for administration or user-facing services.
- Review web-access and application logs for anomalous HTTP requests—unusual lengths, unexpected headers, or repeated probing of management endpoints—that could indicate reconnaissance or exploitation attempts. Correlate with process crashes, unexpected restarts, or new outbound connections from the appliance.
If version or configuration details are unclear, treat the system as potentially affected until the vendor advisory confirms otherwise.
How to remediate
Patch first. Obtain and install the vendor-supplied update that addresses CVE-2025-32756 for each affected product. Follow the installation and reboot guidance in the Fortinet advisory exactly; do not assume a generic FortiOS or other Fortinet patch covers these specific products.
- After patching, verify the new version string matches the fixed release listed by the vendor.
- Harden the remaining attack surface: restrict HTTP/HTTPS management interfaces to trusted administrative networks only, disable unused services, and enforce strong authentication and certificate validation where the product supports them.
- Apply least-privilege principles to any service accounts or integrations that interact with the appliances.
- If the product is cloud-hosted, also follow the applicable BOD 22-01 guidance referenced by CISA.
Document the change and re-scan the environment to confirm no unpatched instances remain.
If you can't patch immediately
Until the vendor update can be applied, reduce exposure with compensating controls:
- Segment the affected appliances so they cannot be reached from the internet or from untrusted internal networks; place them behind firewalls that allow only necessary management and service traffic from known sources.
- If a web application firewall or reverse proxy sits in front of the HTTP interfaces, deploy virtual-patching rules that drop or rate-limit oversized or anomalous requests matching the patterns described in the vendor advisory (once those patterns are published).
- Disable any non-essential HTTP-based features or management interfaces that are not required for operations.
- Increase monitoring: alert on process crashes, unexpected restarts, new listening ports, or outbound connections from the appliances, and retain detailed HTTP access logs for forensic review.
- If mitigations remain unavailable and the risk is unacceptable, plan to discontinue use of the product as directed by CISA until a fix can be installed.
If your data may have been exposed
Actively exploited remote-code-execution vulnerabilities frequently lead to full system compromise and subsequent data theft or lateral movement. If logs or other indicators suggest successful exploitation, treat the appliance and any systems it could reach as potentially breached: isolate them, preserve forensic evidence, and begin incident-response procedures. As a quick personal check, you can run a free exposure scan of your email address against known breach data sets to see whether credentials or other information associated with your accounts have already appeared in public dumps.
AICompiled with AI assistance from public sources and published under our editorial standards.
Details
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H