CyberSec.Space Logo
CVEブラウザに戻る

CVE-2025-32756

🔥 Known Exploited (CISA KEV)CRITICAL
9.8
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2025-05-13
Last Modified2026-06-17
Data SourcesNVDCISA KEV

Vulnerability Description

A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiCamera 1.1 all versions, FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail 7.0.0 through 7.0.8, FortiNDR 7.6.0, FortiNDR 7.4.0 through 7.4.7, FortiNDR 7.2.0 through 7.2.4, FortiNDR 7.0.0 through 7.0.6, FortiRecorder 7.2.0 through 7.2.3, FortiRecorder 7.0.0 through 7.0.5, FortiRecorder 6.4.0 through 6.4.5, FortiVoice 7.2.0, FortiVoice 7.0.0 through 7.0.6, FortiVoice 6.4.0 through 6.4.10 allows a remote unauthenticated attacker to execute arbitrary code or commands via sending HTTP requests with specially crafted hash cookie.

Affected Platforms (CPE)

📦
Fortinet

Fortimail

>= 7.0.0 and < 7.0.9>= 7.2.0 and < 7.2.8>= 7.4.0 and < 7.4.5>= 7.6.0 and < 7.6.3
📦
Fortinet

Fortindr

>= 7.0.0 and < 7.0.7>= 7.2.0 and < 7.2.5>= 7.4.0 and < 7.4.8= 1.1.0= 1.2.0= 1.3.0= 1.4.0= 1.5.0= 7.1.0= 7.1.1= 7.6.0
📦
Fortinet

Fortirecorder

>= 6.4.0 and < 6.4.6>= 7.0.0 and < 7.0.6>= 7.2.0 and < 7.2.4
📦
Fortinet

Fortivoice

>= 6.4.0 and < 6.4.11>= 7.0.0 and < 7.0.7= 7.2.0

References & Advisories

関連する脆弱性情報