• CISA KEV
  • EXPLOITED

CVE-2025-25249: pre-auth remote code execution in Fortinet Multiple Products

An unauthenticated attacker with network access can trigger a heap-based buffer overflow to execute arbitrary code or commands against Fortinet FortiOS and FortiSwitchManager devices (CVE-2025-25249). Affected releases include FortiSwitchManager 7.2.2–7.2.5 and FortiOS 7.6.0–7.6.2, 7.4.0–7.4.7, and 7.2.4–7.2.11; the flaw is exploitable by sending specially crafted packets and does not require valid credentials or user interaction.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.03859
CWE
CWE-122
KEV DUE DATE
PATCH
Not yet

DIRAS TAKE

Treat this as urgent: CISA added CVE-2025-25249 to its Known Exploited Vulnerabilities catalog with a federal remediation deadline, so prioritize mitigations for internet-facing FortiOS and FortiSwitchManager assets immediately.

What is CVE-2025-25249?

An unauthenticated attacker with network access can trigger a heap-based buffer overflow to execute arbitrary code or commands against Fortinet FortiOS and FortiSwitchManager devices (CVE-2025-25249). Affected releases include FortiSwitchManager 7.2.2–7.2.5 and FortiOS 7.6.0–7.6.2, 7.4.0–7.4.7, and 7.2.4–7.2.11; the flaw is exploitable by sending specially crafted packets and does not require valid credentials or user interaction. The weakness is classified as CWE-122 (Heap-based Buffer Overflow).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Fortinet Multiple Products are affected?

BRANCHAFFECTEDFIXED
FortiSwitchManager 7.x7.2.2 – 7.2.5
FortiOS 7.x7.6.0 – 7.6.2
FortiOS 7.x7.4.0 – 7.4.7
FortiOS 7.x7.2.4 – 7.2.11

Is CVE-2025-25249 being exploited?

CISA added this vulnerability to the Known Exploited Vulnerabilities catalog on 2026-09-09, and U.S. federal agencies must address it by 2026-09-12.

How to fix CVE-2025-25249

  1. Apply vendor mitigations and guidance from Fortinet as soon as they are published.
  2. Isolate or remove internet exposure for affected FortiOS and FortiSwitchManager versions until mitigations or patches are available.
  3. Block or filter suspicious packet types and limit access to management interfaces to trusted networks or VPNs.
  4. Monitor device logs and network traffic for anomalous packets or signs of exploitation and prepare for incident response.

Frequently asked questions

Is CVE-2025-25249 being actively exploited?

CISA added CVE-2025-25249 to its Known Exploited Vulnerabilities catalog on 2026-09-09, with a required remediation date of 2026-09-12 for U.S. federal agencies.

Which Fortinet product versions are affected by CVE-2025-25249?

Affected releases listed include FortiSwitchManager 7.2.2–7.2.5 and FortiOS 7.6.0–7.6.2, 7.4.0–7.4.7, and 7.2.4–7.2.11.

Is there a patch for CVE-2025-25249?

No patch was available as of 2026-09-29; follow Fortinet's official guidance and apply recommended mitigations until fixes are released.

Does CVE-2025-25249 require authentication?

No, the vulnerability can be exploited without authentication by sending specially crafted packets to affected FortiOS or FortiSwitchManager devices.

References