CVE-2025-57740

HIGH

FortiOS < 7.2.11, FortiPAM < 1.4.3, FortiProxy < 7.4.4 - Heap-based Buffer Overflow via RDP Bookmark

Title source: llm
STIX 2.1

Description

An Heap-based Buffer Overflow vulnerability [CWE-122] in FortiOS version 7.6.2 and below, version 7.4.7 and below, version 7.2.10 and below, 7.0 all versions, 6.4 all versions; FortiPAM version 1.5.0, version 1.4.2 and below, 1.3 all versions, 1.2 all versions, 1.1 all versions, 1.0 all versions and FortiProxy version 7.6.2 and below, version 7.4.3 and below, 7.2 all versions, 7.0 all versions RDP bookmark connection may allow an authenticated user to execute unauthorized code via crafted requests.

Scores

CVSS v3 7.5
EPSS 0.0062
EPSS Percentile 45.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-122
Status published
Products (19)
Fortinet/FortiOS 6.4.0 - 6.4.16
fortinet/fortios 6.4.0 - 7.2.11
Fortinet/FortiOS 7.0.0 - 7.0.18
Fortinet/FortiOS 7.2.0 - 7.2.10
Fortinet/FortiOS 7.4.0 - 7.4.7
Fortinet/FortiOS 7.6.0 - 7.6.2
fortinet/fortipam 1.5.0
Fortinet/FortiPAM 1.0.0 - 1.0.3
fortinet/fortipam 1.0.0 - 1.4.3
Fortinet/FortiPAM 1.1.0 - 1.1.2
... and 9 more
Published Oct 14, 2025
Tracked Since Feb 18, 2026