CVE-2025-32756
CRITICAL CISA KEVDescription
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiCamera 1.1 all versions, FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail 7.0.0 through 7.0.8, FortiNDR 7.6.0, FortiNDR 7.4.0 through 7.4.7, FortiNDR 7.2.0 through 7.2.4, FortiNDR 7.0.0 through 7.0.6, FortiRecorder 7.2.0 through 7.2.3, FortiRecorder 7.0.0 through 7.0.5, FortiRecorder 6.4.0 through 6.4.5, FortiVoice 7.2.0, FortiVoice 7.0.0 through 7.0.6, FortiVoice 6.4.0 through 6.4.10 allows a remote unauthenticated attacker to execute arbitrary code or commands via sending HTTP requests with specially crafted hash cookie.
CVSS v3.1 Score
CISA Known Exploited Vulnerability
This vulnerability is actively exploited in the wild.
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| fortinet | fortimail |
| fortinet | fortimail |
| fortinet | fortimail |
| fortinet | fortimail |
| fortinet | fortindr |
| fortinet | fortindr |
| fortinet | fortindr |
| fortinet | fortindr |
| fortinet | fortindr |
| fortinet | fortindr |
| fortinet | fortindr |
| fortinet | fortindr |
| fortinet | fortindr |
| fortinet | fortindr |
| fortinet | fortindr |
| fortinet | fortirecorder |
| fortinet | fortirecorder |
| fortinet | fortirecorder |
| fortinet | fortivoice |
| fortinet | fortivoice |
| fortinet | fortivoice |
| fortinet | forticamera_firmware |
| fortinet | forticamera |
| fortinet | forticamera_firmware |
| fortinet | forticamera |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2025-32756? +
How severe is CVE-2025-32756? +
What products are affected by CVE-2025-32756? +
How do I check if I'm vulnerable to CVE-2025-32756? +
Related Vulnerabilities
editorconfig-core-c is an EditorConfig core library for use by plugins supporting EditorConfig parsing. Versions up to and including 0.12.10 have …
Under certain circumstances the iSTAR Configuration Utility (ICU) tool could have a buffer overflow issue
A stack buffer overflow has been identified in the AsIO3.sys driver. This vulnerability can be triggered by input manipulation, may …
CWE-121: Stack-based Buffer Overflow vulnerability exists that could cause local attackers being able to exploit these issues to potentially execute …
Stack-based buffer overflow vulnerability in the 'conn-indicator' binary running as root on the TP-Link Archer AX50 router, in firmware versions …
PCSX2 is a free and open-source PlayStation 2 (PS2) emulator. A stack-based buffer overflow exists in the Kprintf_HLE function of …