← All CVEs NewScan detects
highKEV

CVE-2025-25249

FortiOS heap-based buffer overflow (CVSS 8.1, CISA KEV) - exploited in the wild by the PivotC2 FortiGate RAT

Severity
high
Affected product
FortiOS SSL-VPN
Affected versions
FortiOS SSL-VPN ≥ 7.6.0, ≤ 7.6.3
Affected versions
FortiOS SSL-VPN ≥ 7.4.0, ≤ 7.4.8
Affected versions
FortiOS SSL-VPN ≥ 7.2.0, ≤ 7.2.11
Affected versions
FortiOS SSL-VPN ≥ 7.0.0, ≤ 7.0.17
Fixed in
FortiOS SSL-VPN 7.6.4
Fixed in
FortiOS SSL-VPN 7.4.9
Fixed in
FortiOS SSL-VPN 7.2.12
Fixed in
FortiOS SSL-VPN 7.0.18
CISA KEV
Listed as a known exploited vulnerability
EPSS
1% chance of exploitation in the next 30 days
Added to NewScan
2026-09-10
Detected by
NewScan — free, self-hosted

How NewScan reports it

APPLIANCE FINGERPRINT

NewScan fingerprints the FortiOS SSL-VPN appliance and reports this CVE when the detected version falls inside the affected range below.

Added 2026-09-10. FOUR PER-BRANCH ROWS FOR ONE CVE, one per FortiOS train, because Fortinet fixes each train separately (7.6.4 / 7.4.9 / 7.2.12 / 7.0.18) - a single widened bound would call a fully patched 7.4.9 vulnerable via the 7.6 bound, the Confluence CVE-2023-22518 mistake this file already carries a warning about. This is the 7.6 arm. Only the four ranges the advisory states verbatim are written; the NVD description continues past them and any further train (or FortiProxy) is deliberately NOT claimed here - under-reporting beats asserting a range we did not read, same call as the Traefik 2.x rows. Version source is the EXISTING `FortiGate <ver>` banner regex on this appliance's fingerprint, already shipping for CVE-2024-21762 - not a new one - and an install that publishes only `7.6` with no patch level now falls outside every arm and degrades to the advisory observation (techdb._too_coarse, added with these rows).

APPLIANCE FINGERPRINT

NewScan fingerprints the FortiOS SSL-VPN appliance and reports this CVE when the detected version falls inside the affected range below.

The 7.4 arm of CVE-2025-25249 - see the 7.6 row for why the branch is split.

APPLIANCE FINGERPRINT

NewScan fingerprints the FortiOS SSL-VPN appliance and reports this CVE when the detected version falls inside the affected range below.

The 7.2 arm of CVE-2025-25249 - see the 7.6 row for why the branch is split.

APPLIANCE FINGERPRINT

NewScan fingerprints the FortiOS SSL-VPN appliance and reports this CVE when the detected version falls inside the affected range below.

The 7.0 arm of CVE-2025-25249 - see the 7.6 row for why the branch is split.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →