Record summary

CVE-2025-57740 has a selected CVSS score of 6.7 (medium).

Description

An Heap-based Buffer Overflow vulnerability [CWE-122] in FortiOS version 7.6.2 and below, version 7.4.7 and below, version 7.2.10 and below, 7.0 all versions, 6.4 all versions; FortiPAM version 1.5.0, version 1.4.2 and below, 1.3 all versions, 1.2 all versions, 1.1 all versions, 1.0 all versions and FortiProxy version 7.6.2 and below, version 7.4.3 and below, 7.2 all versions, 7.0 all versions RDP bookmark connection may allow an authenticated user to execute unauthorized code via crafted requests.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 16, 2025 · Source: CVE List

Affected products and versions

4
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List7.6.0 to ≤ 7.6.2affected
7.4.0 to ≤ 7.4.7affected
7.2.0 to ≤ 7.2.10affected
7.0.0 to ≤ 7.0.18affected
6.4.0 to ≤ 6.4.16affected

Default status: unaffected

CVE List1.5.0affected
1.4.0 to ≤ 1.4.2affected
1.3.0 to ≤ 1.3.1affected
1.2.0affected
1.1.0 to ≤ 1.1.2affected
1.0.0 to ≤ 1.0.3affected

Default status: unaffected

CVE List7.6.0 to ≤ 7.6.2affected
7.4.0 to ≤ 7.4.3affected
7.2.0 to ≤ 7.2.15affected
7.0.0 to ≤ 7.0.22affected

Default status: unknown

CVE ListBefore *affected

References

3