FortiOS and FortiSwitchManager Vulnerability Enables Remote Code Execution

FortiOS and FortiSwitchManager Vulnerability Enables Remote Code Execution

First seen 14 Jan 2026, 09:52 UTC CybersecuritynewsGbhackersCyberpress 92% similarity 57.2

Article Content

Browse articles
ThreatCluster

Fortinet disclosed a critical heap-based buffer overflow vulnerability in the cw_acd daemon of FortiOS and FortiSwitchManager, tracked as CVE-2025-25249. This flaw allows remote unauthenticated attackers to execute arbitrary code on affected systems, posing a significant risk to organizations using Fortinet's products. The vulnerability has a CVSS v3.1 score of 7.4.

ThreatCluster AI How this analysis works

Community

Browse all →

Tracked Entities in This Story