SecPod

Learn Search

Search across all Learn content

← Back to Security Research
FortiFlaw: Critical Stack-Based Buffer Overflow in Multiple Fortinet Products

FortiFlaw: Critical Stack-Based Buffer Overflow in Multiple Fortinet Products

A critical zero-day vulnerability, tracked as CVE-2025-32756 and assigned a CVSS score of 9.8, has been discovered in several Fortinet products, including FortiVoice, FortiMail, FortiNDR, FortiRecorder, and FortiCamera. This flaw allows remote, unauthenticated attackers to execute arbitrary code or ...

May 14, 2025By Santosh Sethuraman3 min read

A critical zero-day vulnerability, tracked as CVE-2025-32756 and assigned a CVSS score of 9.8, has been discovered in several Fortinet products, including FortiVoice, FortiMail, FortiNDR, FortiRecorder, and FortiCamera. This flaw allows remote, unauthenticated attackers to execute arbitrary code or commands by sending specially crafted HTTP requests.

The vulnerability is actively exploited in the wild, particularly targeting FortiVoice systems. While the full scale of these attacks and the identity of the threat actors remain unclear, observed activity suggests a high level of sophistication. Attackers have been seen performing network scans, erasing system crash logs, and enabling fcgi debugging, a technique used to capture credentials from the system or intercept SSH login attempts.

Technical Details

The root cause of this vulnerability lies in improper bounds checking during HTTP request processing. Bounds checking ensures input data does not exceed the allocated memory space. In this case, the flaw occurs due to insufficient validation of specific fields within HTTP requests, such as headers, cookies, or parameters.

Attackers can exploit this weakness by sending specially crafted HTTP cookies. Although these cookies are typically hashed to prevent tampering and improve security, the vulnerable systems fail to validate their size and content before processing correctly. An attacker triggers a stack-based buffer overflow by sending a cookie with a specially crafted hash value that exceeds the expected size or contains malicious data.

This overflow causes excess data to overwrite adjacent memory on the stack, allowing the attacker to manipulate the application’s execution flow and potentially execute arbitrary code or commands on the affected system without requiring authentication.

Some indicators of compromise for the above vulnerability include suspicious HTTP requests with abnormally large cookie values, unusual system processes or user accounts, enabled fcgi debugging not configured by administrators, erased or missing system crash logs.

Impact

This vulnerability can be particularly dangerous because it can be exploited remotely without authentication. Successful exploitation could allow malicious code to execute with the same privileges as the application, leading to unauthorized access, data exfiltration, or further compromise of the network.

Products affected

The issue affects the following products and versions –

  • FortiCamera versions 1.1, 2.0, 2.1.x
  • FortiMail versions 7.0.x, 7.2.x, 7.4.x, 7.6.x
  • FortiNDR versions 1.1, 1.2, 1.3, 1.4, 1.5, 7.1, 7.0.x, 7.2.x, 7.4.x, 7.6.x
  • FortiRecorder versions 6.4.x, 7.0.x, 7.2.x
  • FortiVoice versions 6.4.x, 7.0.x, 7.2.x

Solution and Mitigation

The issue can be fixed by upgrading the software to any of the following versions-

  • FortiCamera to version 2.1.4 or above.
  • FortiMail to version 7.0.9, 7.2.8, 7.4.5, 7.6.3 or above.
  • FortiNDR to version 7.0.7, 7.2.5, 7.4.8, 7.6.1 or above.
  • FortiRecorder to version 6.4.6, 7.0.6, 7.2.4 or above
  • FortiVoice to version 6.4.11, 7.0.7, 7.2.1 or above.

Instantly Fix Risks with SanerNow Patch Management

SanerNow patch management is a continuous, automated, and integrated software that instantly fixes risks exploited in the wild. The software supports major operating systems like Windows, Linux, and macOS, as well as 550+ third-party applications.

It also allows you to set up a safe testing area to test patches before deploying them in a primary production environment. SanerNow patch management additionally supports a patch rollback feature in case of patch failure or a system malfunction.

Experience the fastest and most accurate patching software here.

Featured Posts

Open Operation CameraSwarm: Inside the Toolkit Behind 14,530 Compromised Dahua Cameras
Operation CameraSwarm: Inside the Toolkit Behind 14,530 Compromised Dahua Cameras

CVE Research

Operation CameraSwarm: Inside the Toolkit Behind 14,530 Compromised Dahua Cameras

A single operator compromised 14,530+ Dahua cameras across Ukraine and Russia in 35 days, chaining credential brute-force, a CVE-2021-33044/33045 authentication bypass, and P2P relay abuse to plant a persistent backdoor and harvest transferable admin access.

Aug 21, 2026

Open Critical GitLab Flaw Exposes Public Projects to Deletion — Two CVEs Patched, Including High-Severity CSRF
Critical GitLab Flaw Exposes Public Projects to Deletion — Two CVEs Patched, Including High-Severity CSRF

CVE Research

Critical GitLab Flaw Exposes Public Projects to Deletion — Two CVEs Patched, Including High-Severity CSRF

CVE-2026-19478 is a critical code injection vulnerability in GitLab CE/EE that allows an unauthenticated attacker to modify or delete public projects and user data by abusing a GraphQL directive. A second high-severity issue, CVE-2026-19650, involves cross-site request forgery in the GraphQL multiplex query handler. This article examines how the critical vulnerability works, the availability of a public proof-of-concept, the potential impact on self-managed instances, the affected versions, and the security updates released to remediate both issues.

Aug 19, 2026

Open No Password Needed: macOS Screen Sharing Flaw (CVE-2026-65400) Used to Deploy Monero Miners
No Password Needed: macOS Screen Sharing Flaw (CVE-2026-65400) Used to Deploy Monero Miners

CVE Research

No Password Needed: macOS Screen Sharing Flaw (CVE-2026-65400) Used to Deploy Monero Miners

Aug 19, 2026

Open Evooo1Bot: Mirai-Based Linux Botnet Turns Edge Devices Into SOCKS5 Proxies
Evooo1Bot: Mirai-Based Linux Botnet Turns Edge Devices Into SOCKS5 Proxies

CVE Research

Evooo1Bot: Mirai-Based Linux Botnet Turns Edge Devices Into SOCKS5 Proxies

Aug 19, 2026