Skip to content

Heap Based Buffer Overflow In Fortios And Fortiswitchmanager Allows Cve 2025 25249

exploitbulletin.com September 9, 2026

Heap-based buffer overflow in FortiOS and FortiSwitchManager allows unauthenticated code execution (CVE-2025-25249)

The CVE was added to VulnCheck's known-exploited catalog on 2026-09-08 with a report of a purpose-built FortiGate RAT being planted on unpatched devices, so any FortiGate or FortiSwitchManager still on an affected build should be updated as an emergency change rather than in the window.

A heap overflow reachable via specially crafted packets lets an attacker execute unauthorized code or commands on FortiOS and FortiSwitchManager devices without credentials. Reporting describes compromised devices being fitted with a Node.js post-exploitation RAT (PivotC2).

Affected: FortiOS 7.6.0–7.6.3; FortiOS 7.4.0–7.4.8; FortiOS 7.2.0–7.2.11; FortiOS 7.0.0–7.0.17; FortiOS 6.4 (all versions); FortiSwitchManager 7.2.0–7.2.6; FortiSwitchManager 7.0.0–7.0.5; Siemens RUGGEDCOM APE1808 with Fortinet NGFW < V7.4.9

Run `get system status` on each FortiOS/FortiGate device and FortiSwitchManager instance and compare the build against the affected ranges above (for RUGGEDCOM APE1808, any Fortinet NGFW before V7.4.9). Treat a device that ran an affected build while its management or fabric-enabled interface was reachable from an untrusted network as potentially compromised: look for unexpected Node.js processes and outbound connections you cannot attribute (the PivotC2 RAT), unexplained crashes or restarts of the affected daemon, and unauthorised changes to admin accounts, VPN configuration and scheduled tasks.

Upgrade FortiOS/FortiGate NGFW to a fixed build (Siemens directs RUGGEDCOM APE1808 users to Fortinet NGFW V7.4.9 or later) and FortiSwitchManager beyond the affected 7.0.x/7.2.x ranges, following FG-IR-25-084. Where an upgrade cannot be applied immediately, apply the per-interface mitigation in FG-IR-25-084 / Siemens SSA-864900 — remove "fabric" access from each interface — and keep management interfaces off untrusted networks. Rotate device credentials and certificates on any appliance that ran an affected build while reachable from the internet.