CVE-2025-25249
FortiOS heap-based buffer overflow (CVSS 8.1, CISA KEV) - exploited in the wild by the PivotC2 FortiGate RAT
- Severity
- high
- Affected product
- FortiOS SSL-VPN
- Affected versions
- FortiOS SSL-VPN ≥ 7.6.0, ≤ 7.6.3
- Affected versions
- FortiOS SSL-VPN ≥ 7.4.0, ≤ 7.4.8
- Affected versions
- FortiOS SSL-VPN ≥ 7.2.0, ≤ 7.2.11
- Affected versions
- FortiOS SSL-VPN ≥ 7.0.0, ≤ 7.0.17
- Fixed in
- FortiOS SSL-VPN 7.6.4
- Fixed in
- FortiOS SSL-VPN 7.4.9
- Fixed in
- FortiOS SSL-VPN 7.2.12
- Fixed in
- FortiOS SSL-VPN 7.0.18
- CISA KEV
- Listed as a known exploited vulnerability
- EPSS
- 1% chance of exploitation in the next 30 days
- Added to NewScan
- 2026-09-10
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
APPLIANCE FINGERPRINT
NewScan fingerprints the FortiOS SSL-VPN appliance and reports this CVE when the detected version falls inside the affected range below.
Added 2026-09-10. FOUR PER-BRANCH ROWS FOR ONE CVE, one per FortiOS train, because Fortinet fixes each train separately (7.6.4 / 7.4.9 / 7.2.12 / 7.0.18) - a single widened bound would call a fully patched 7.4.9 vulnerable via the 7.6 bound, the Confluence CVE-2023-22518 mistake this file already carries a warning about. This is the 7.6 arm. Only the four ranges the advisory states verbatim are written; the NVD description continues past them and any further train (or FortiProxy) is deliberately NOT claimed here - under-reporting beats asserting a range we did not read, same call as the Traefik 2.x rows. Version source is the EXISTING `FortiGate <ver>` banner regex on this appliance's fingerprint, already shipping for CVE-2024-21762 - not a new one - and an install that publishes only `7.6` with no patch level now falls outside every arm and degrades to the advisory observation (techdb._too_coarse, added with these rows).
APPLIANCE FINGERPRINT
NewScan fingerprints the FortiOS SSL-VPN appliance and reports this CVE when the detected version falls inside the affected range below.
The 7.4 arm of CVE-2025-25249 - see the 7.6 row for why the branch is split.
APPLIANCE FINGERPRINT
NewScan fingerprints the FortiOS SSL-VPN appliance and reports this CVE when the detected version falls inside the affected range below.
The 7.2 arm of CVE-2025-25249 - see the 7.6 row for why the branch is split.
APPLIANCE FINGERPRINT
NewScan fingerprints the FortiOS SSL-VPN appliance and reports this CVE when the detected version falls inside the affected range below.
The 7.0 arm of CVE-2025-25249 - see the 7.6 row for why the branch is split.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →