Skip to content

FortiOS and FortiSwitchManager Flaw Allows Remote Code Execution

Gbhackers •Divya • January 14, 2026

A high heap-based buffer overflow vulnerability in the cw_acd daemon component of Fortinet’s FortiOS and FortiSwitchManager has been disclosed, enabling remote unauthenticated attackers to execute arbitrary code on affected systems. The vulnerability, tracked as CVE-2025-25249, carries a high CVSS v3.1 score of 7.4 and poses significant risk to enterprise network infrastructure. Vulnerability Details The flaw […]

Extracted Entities

Attack Types (1)