CVE-2025-32756

A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiVoice versions 7.2.0, 7.0.0 through 7.0.6, 6.4.0 through 6.4.10, FortiRecorder versions 7.2.0 through 7.2.3, 7.0.0 through 7.0.5, 6.4.0 through 6.4.5, FortiMail versions 7.6.0 through 7.6.2, 7.4.0 through 7.4.4, 7.2.0 through 7.2.7, 7.0.0 through 7.0.8, FortiNDR versions 7.6.0, 7.4.0 through 7.4.7, 7.2.0 through 7.2.4, 7.0.0 through 7.0.6, FortiCamera versions 2.1.0 through 2.1.3, 2.0 all versions, 1.1 all versions, allows a remote unauthenticated attacker to execute arbitrary code or commands via sending HTTP requests with specially crafted hash cookie.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fortinet:fortimail:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimail:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimail:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortimail:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortindr:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortindr:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortindr:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortindr:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortindr:1.2.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortindr:1.3.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortindr:1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortindr:1.5.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortindr:7.1.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortindr:7.1.1:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortindr:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortirecorder:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortirecorder:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortirecorder:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortivoice:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortivoice:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortivoice:7.2.0:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:fortinet:forticamera_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fortinet:forticamera:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:fortinet:forticamera_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fortinet:forticamera:-:*:*:*:*:*:*:*

History

24 Oct 2025, 12:53

Type Values Removed Values Added
References () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-32756 - () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-32756 - US Government Resource

21 Oct 2025, 23:17

Type Values Removed Values Added
References
  • () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-32756 -

21 Oct 2025, 20:20

Type Values Removed Values Added
References
  • {'url': 'https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-32756', 'source': '134c704f-9b21-4f2e-91b3-4a467353bcc0'}

21 Oct 2025, 19:21

Type Values Removed Values Added
References
  • () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-32756 -

16 May 2025, 19:41

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-13 15:15

Updated : 2025-10-24 12:53


NVD link : CVE-2025-32756

Mitre link : CVE-2025-32756

CVE.ORG link : CVE-2025-32756


JSON object : View

Products Affected

fortinet

  • fortivoice
  • forticamera
  • fortindr
  • fortimail
  • forticamera_firmware
  • fortirecorder
CWE
CWE-121

Stack-based Buffer Overflow

CWE-787

Out-of-bounds Write