CVE-2025-32756
CRITICAL KEV RANSOMWAREFortinet Fortimail < 7.0.9 - Out-of-Bounds Write
Title source: ruleDescription
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiCamera 1.1 all versions, FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail 7.0.0 through 7.0.8, FortiNDR 7.6.0, FortiNDR 7.4.0 through 7.4.7, FortiNDR 7.2.0 through 7.2.4, FortiNDR 7.0.0 through 7.0.6, FortiRecorder 7.2.0 through 7.2.3, FortiRecorder 7.0.0 through 7.0.5, FortiRecorder 6.4.0 through 6.4.5, FortiVoice 7.2.0, FortiVoice 7.0.0 through 7.0.6, FortiVoice 6.4.0 through 6.4.10 allows a remote unauthenticated attacker to execute arbitrary code or commands via sending HTTP requests with specially crafted hash cookie.
Exploits (7)
github
WRITEUP
7 stars
by cybersecplayground · poc
https://github.com/cybersecplayground/PoC-and-CVE-Reports/tree/main/2025/CVE-2025-32756.md
Scores
CVSS v3
9.8
EPSS
0.2228
EPSS Percentile
95.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CISA KEV
2025-05-14
VulnCheck KEV
2025-05-13
ENISA EUVD
EUVD-2025-14705
Ransomware Use
Confirmed
CWE
CWE-121
CWE-787
Status
published
Products (14)
fortinet/forticamera_firmware
2.0.0 - 2.1.3
fortinet/fortimail
7.0.0 - 7.0.9
fortinet/fortindr
1.1.0
fortinet/fortindr
1.2.0
fortinet/fortindr
1.3.0
fortinet/fortindr
1.4.0
fortinet/fortindr
1.5.0
fortinet/fortindr
7.1.0
fortinet/fortindr
7.1.1
fortinet/fortindr
7.6.0
... and 4 more
Published
May 13, 2025
KEV Added
May 14, 2025
Tracked Since
Feb 18, 2026