CVE-2025-32756
KEVlargeStack-based overflow RCE in Fortinet FortiMail, FortiVoice, FortiNDR, FortiFone
CISA: Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability
CVE-2025-32756 is a stack-based buffer overflow (CWE-124) in Fortinet's FortiMail, FortiVoice, FortiNDR and FortiFone products that is reachable over the network and requires no authentication. An attacker triggers the flaw by sending crafted HTTP requests to the affected device's web-facing service. Successful exploitation yields arbitrary code or command execution on the appliance, giving the attacker control of the device and any traffic or data it handles (such as email or voice services). Organizations running these Fortinet appliances or phones are affected, particularly where the devices are reachable from the internet. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-05-14, confirming exploitation in the wild; no public proof-of-concept is known, ransomware use is unconfirmed, and EPSS puts its 30-day exploitation probability at about 30% (98th percentile).
What to do: Inventory your environment for FortiMail, FortiVoice, FortiNDR and FortiFone deployments and apply the patched releases specified in Fortinet's advisory for CVE-2025-32756. Until patched, restrict internet exposure of the affected devices' HTTP/HTTPS interfaces (limit admin and web access to trusted networks/VPN) per vendor mitigation guidance, and review device logs for signs of exploitation. Federal agencies must apply the required mitigations or discontinue use per BOD 22-01 deadlines.
| Fortinet FortiMail | — |
| Fortinet FortiVoice | — |
| Fortinet FortiNDR | — |
| Fortinet FortiFone | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiCamera 1.1 all versions, FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail 7.0.0 through 7.0.8, FortiNDR 7.6.0, FortiNDR 7.4.0 through 7.4.7, FortiNDR 7.2.0 through 7.2.4, FortiNDR 7.0.0 through 7.0.6, FortiRecorder 7.2.0 through 7.2.3, FortiRecorder 7.0.0 through 7.0.5, FortiRecorder 6.4.0 through 6.4.5, FortiVoice 7.2.0, FortiVoice 7.0.0 through 7.0.6, FortiVoice 6.4.0 through 6.4.10 allows a remote unauthenticated attacker to execute arbitrary code or commands via sending HTTP requests with specially crafted hash cookie.
- Affected
- Fortinet Multiple Products
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- fortinet
- Products
- fortimail, fortindr, fortirecorder, fortivoice, forticamera firmware
- Weakness
- CWE-121, CWE-787
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H