DIRAS TAKE
Treat this as urgent: CISA added CVE-2025-25249 to its Known Exploited Vulnerabilities catalog with a federal remediation deadline, so prioritize mitigations for internet-facing FortiOS and FortiSwitchManager assets immediately.
What is CVE-2025-25249?
An unauthenticated attacker with network access can trigger a heap-based buffer overflow to execute arbitrary code or commands against Fortinet FortiOS and FortiSwitchManager devices (CVE-2025-25249). Affected releases include FortiSwitchManager 7.2.2–7.2.5 and FortiOS 7.6.0–7.6.2, 7.4.0–7.4.7, and 7.2.4–7.2.11; the flaw is exploitable by sending specially crafted packets and does not require valid credentials or user interaction. The weakness is classified as CWE-122 (Heap-based Buffer Overflow).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Fortinet Multiple Products are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| FortiSwitchManager 7.x | 7.2.2 – 7.2.5 | |
| FortiOS 7.x | 7.6.0 – 7.6.2 | |
| FortiOS 7.x | 7.4.0 – 7.4.7 | |
| FortiOS 7.x | 7.2.4 – 7.2.11 |
Is CVE-2025-25249 being exploited?
CISA added this vulnerability to the Known Exploited Vulnerabilities catalog on 2026-09-09, and U.S. federal agencies must address it by 2026-09-12.
How to fix CVE-2025-25249
- Apply vendor mitigations and guidance from Fortinet as soon as they are published.
- Isolate or remove internet exposure for affected FortiOS and FortiSwitchManager versions until mitigations or patches are available.
- Block or filter suspicious packet types and limit access to management interfaces to trusted networks or VPNs.
- Monitor device logs and network traffic for anomalous packets or signs of exploitation and prepare for incident response.
Frequently asked questions
Is CVE-2025-25249 being actively exploited?
CISA added CVE-2025-25249 to its Known Exploited Vulnerabilities catalog on 2026-09-09, with a required remediation date of 2026-09-12 for U.S. federal agencies.
Which Fortinet product versions are affected by CVE-2025-25249?
Affected releases listed include FortiSwitchManager 7.2.2–7.2.5 and FortiOS 7.6.0–7.6.2, 7.4.0–7.4.7, and 7.2.4–7.2.11.
Is there a patch for CVE-2025-25249?
No patch was available as of 2026-09-29; follow Fortinet's official guidance and apply recommended mitigations until fixes are released.
Does CVE-2025-25249 require authentication?
No, the vulnerability can be exploited without authentication by sending specially crafted packets to affected FortiOS or FortiSwitchManager devices.
References
- nvd.nist.gov/vuln/detail/CVE-2025-25249
- cve.org/CVERecord?id=CVE-2025-25249
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-25249
- fortiguard.fortinet.com/psirt/FG-IR-25-084
- All Fortinet CVEs on CVE Radar
- CVEs published in September 2026