CVE-2025-32756
Description
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiCamera 1.1 all versions, FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail 7.0.0 through 7.0.8, FortiNDR 7.6.0, FortiNDR 7.4.0 through 7.4.7, FortiNDR 7.2.0 through 7.2.4, FortiNDR 7.0.0 through 7.0.6, FortiRecorder 7.2.0 through 7.2.3, FortiRecorder 7.0.0 through 7.0.5, FortiRecorder 6.4.0 through 6.4.5, FortiVoice 7.2.0, FortiVoice 7.0.0 through 7.0.6, FortiVoice 6.4.0 through 6.4.10 allows a remote unauthenticated attacker to execute arbitrary code or commands via sending HTTP requests with specially crafted hash cookie.
CVSS Details
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Threat Intelligence
- Added
- May 14, 2025
- Due
- Jun 4, 2025
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Weaknesses 2
Affected Products 25
| Vendor | Product | Version | Range |
|---|---|---|---|
| fortinet | fortimail | * | ≥7.0.0 – <7.0.9 |
| fortinet | fortimail | * | ≥7.2.0 – <7.2.8 |
| fortinet | fortimail | * | ≥7.4.0 – <7.4.5 |
| fortinet | fortimail | * | ≥7.6.0 – <7.6.3 |
| fortinet | fortindr | * | ≥7.0.0 – <7.0.7 |
| fortinet | fortindr | * | ≥7.2.0 – <7.2.5 |
| fortinet | fortindr | * | ≥7.4.0 – <7.4.8 |
| fortinet | fortindr | 1.1.0 | any |
| fortinet | fortindr | 1.2.0 | any |
| fortinet | fortindr | 1.3.0 | any |
| fortinet | fortindr | 1.4.0 | any |
| fortinet | fortindr | 1.5.0 | any |
| fortinet | fortindr | 7.1.0 | any |
| fortinet | fortindr | 7.1.1 | any |
| fortinet | fortindr | 7.6.0 | any |
| fortinet | fortirecorder | * | ≥6.4.0 – <6.4.6 |
| fortinet | fortirecorder | * | ≥7.0.0 – <7.0.6 |
| fortinet | fortirecorder | * | ≥7.2.0 – <7.2.4 |
| fortinet | fortivoice | * | ≥6.4.0 – <6.4.11 |
| fortinet | fortivoice | * | ≥7.0.0 – <7.0.7 |
| fortinet | fortivoice | 7.2.0 | any |
| fortinet | forticamera_firmware | * | ≥2.0.0 – ≤2.1.3 |
| fortinet | forticamera | * | any |
| fortinet | forticamera_firmware | * | ≥1.1.0 – ≤1.1.5 |
| fortinet | forticamera | * | any |
References 2
- fortiguard.fortinet.com https://fortiguard.fortinet.com/psirt/FG-IR-25-254
- cisa.gov https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-32756
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.